QueryPie Community Edition is live ๐ŸŽ‰ Get it now for free Download today!

๋ฌด๋ฃŒ๋กœ ์‹œ์ž‘ํ•˜๊ธฐ
๋ฐฑ์„œ

MCP ๋ณด์•ˆ์„ฑ ํ‰๊ฐ€: ๋ฌธํ—Œ ์กฐ์‚ฌ๋ฅผ ํ†ตํ•œ MCP ๋ณด์•ˆ ์œ„ํ˜‘ ์‹๋ณ„ ๋ฐ ์ทจ์•ฝ์  ๋ถ„์„

AI ์‹œ์Šคํ…œ ๊ฐ„ ํ˜‘์—…๊ณผ ๋ฌธ๋งฅ ๊ณต์œ ๋ฅผ ์œ„ํ•œ ์ƒˆ๋กœ์šด ํ‘œ์ค€, Model Context Protocol(MCP). ๋ณธ ๋ฐฑ์„œ๋Š” MCP ๊ธฐ๋ฐ˜ ์‹œ์Šคํ…œ์˜ ๊ตฌ์กฐ์™€ ๋ณด์•ˆ ์œ„ํ˜‘์„ ๋ถ„์„ํ•˜๊ณ , Zero Trust ๋Œ€์‘ ์ „๋žต๊ณผ ์ƒˆ๋กœ์šด ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜ โ€˜MCP PAMโ€™์„ ์ œ์•ˆํ•ฉ๋‹ˆ๋‹ค.

Kenny Park

Kenny Park

CISO

์ผ€๋‹ˆ๋Š” QueryPie์˜ CISO์ด์ž ๊ธ€๋กœ๋ฒŒ ๋””๋ ‰ํ„ฐ๋กœ ์ •๋ณด ๋ณด์•ˆ, ํด๋ผ์šฐ๋“œ ์ปดํ“จํŒ… ๋ฐ ๊ธ€๋กœ๋ฒŒ ์šด์˜์— ๋Œ€ํ•œ 20๋…„ ์ด์ƒ์˜ ๊ฒฝํ—˜์„ ๋ณด์œ ํ–ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Š” QueryPie์˜ ๊ธ€๋กœ๋ฒŒ ์ „๋žต์„ ์ด๋„๋Š” ๋™์‹œ์— ์ œํ’ˆ์— ์ตœ์ƒ์˜ ๋ณด์•ˆ๊ณผ ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ๋ณด์žฅํ•˜๋Š” ์—ญํ• ์„ ํ•˜์˜€์Šต๋‹ˆ๋‹ค. ์ผ€๋‹ˆ๋Š” ๊ฐ•๋ ฅํ•œ ๋ณด์•ˆ ํ”„๋ ˆ์ž„์›Œํฌ ๊ตฌ์ถ•, ํด๋ผ์šฐ๋“œ ์ธํ”„๋ผ ๊ด€๋ฆฌ, ํ˜์‹  ์ด‰์ง„ ๋“ฑ์—์„œ ์ค‘์š”ํ•œ ์„ฑ๊ณผ๋ฅผ ๊ฑฐ๋‘์—ˆ์Šต๋‹ˆ๋‹ค.

2025๋…„ 4์›” 16์ผ

MCP ๋ณด์•ˆ์„ฑ ํ‰๊ฐ€: ๋ฌธํ—Œ ์กฐ์‚ฌ๋ฅผ ํ†ตํ•œ MCP ๋ณด์•ˆ ์œ„ํ˜‘ ์‹๋ณ„ ๋ฐ ์ทจ์•ฝ์  ๋ถ„์„

1. ์„œ๋ก  ๋ฐ ๋ถ„์„ ๋ชฉ์ 

๋ฐฐ๊ฒฝ ๋ฐ ํ•„์š”์„ฑ

AI ์‹œ์Šคํ…œ์˜ ์ƒ์šฉํ™”๊ฐ€ ๊ธ‰์†๋„๋กœ ํ™•์‚ฐ๋จ์— ๋”ฐ๋ผ, ์‹œ์Šคํ…œ ๊ฐ„ ์ƒํ˜ธ์ž‘์šฉ ๋ฐ ๋ฌธ๋งฅ ์ •๋ณด(Context) ๊ณต์œ ๋Š” ๋ชจ๋ธ์˜ ์ •ํ™•์„ฑ, ์ถ”๋ก  ๋งฅ๋ฝ ์œ ์ง€, ๋Œ€์‘ ์œ ์—ฐ์„ฑ์„ ๊ฒฐ์ •์ง“๋Š” ํ•ต์‹ฌ ์š”์†Œ๊ฐ€ ๋˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ํ™˜๊ฒฝ ์†์—์„œ ๋“ฑ์žฅํ•œ Model Context Protocol (MCP)๋Š” ๋Œ€๊ทœ๋ชจ ์–ธ์–ด๋ชจ๋ธ(LLM) ๋ฐ ์—์ด์ „ํŠธ ๊ธฐ๋ฐ˜ ์‹œ์Šคํ…œ์—์„œ ๋ฌธ๋งฅ ์ •๋ณด๋ฅผ ๊ตฌ์กฐํ™”ํ•˜๊ณ  ํ‘œ์ค€ํ™”๋œ ๋ฐฉ์‹์œผ๋กœ ์ „๋‹ฌํ•˜๊ธฐ ์œ„ํ•œ ์ƒˆ๋กœ์šด ํ”„๋ ˆ์ž„์›Œํฌ๋กœ ์ฃผ๋ชฉ๋ฐ›๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค[1]. MCP๋Š” ๋ฌธ๋งฅ ํ๋ฆ„(context flow)์„ ํ†ตํ•ด ๋ชจ๋ธ ๊ฐ„ ํ˜‘๋ ฅ, ์‹คํ–‰ ๋งฅ๋ฝ ๊ณต์œ , ์ •์ฑ… ๊ธฐ๋ฐ˜ ๊ถŒํ•œ ์ œ์–ด ๋“ฑ์„ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•˜๋ฉฐ, ํŠนํžˆ ์ œ๋กœ ํŠธ๋Ÿฌ์ŠคํŠธ(Zero Trust) ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜์™€์˜ ๊ฒฐํ•ฉ ๊ฐ€๋Šฅ์„ฑ ์ธก๋ฉด์—์„œ ์ „๋žต์  ๊ฐ€์น˜๋ฅผ ์ง€๋‹ˆ๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค[2]. ํ•˜์ง€๋งŒ ์•„์ง๊นŒ์ง€ MCP๋Š” ์„ค๊ณ„ ๋ฐ ๊ตฌํ˜„ ๋ฉด์—์„œ ์ดˆ๊ธฐ ๋‹จ๊ณ„์— ๋จธ๋ฌผ๋Ÿฌ ์žˆ์œผ๋ฉฐ, ๊ทธ ๊ตฌ์กฐ์  ํŠน์„ฑ์ƒ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ฃผ์š” ๋ณด์•ˆ ์œ„ํ˜‘์ด ๋™๋ฐ˜๋˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค:

  • ๋‹ค๊ณ„์ธต ๋ฌธ๋งฅ ์˜ค์šฉ(Context Misuse)
  • ์ธ์ฆ ์œ„์ž„์˜ ๋‚จ์šฉ(Delegation Exploit)
  • ์ •์ฑ… ์šฐํšŒ ๋ฐ LLM ์˜ค์ž‘๋™(Misbehaving Models)[3][4]

์ด๋Ÿฌํ•œ ์œ„ํ˜‘์€ ๋‹จ์ˆœํ•œ ๋ณด์•ˆ๊ตฌ์„ฑ ์˜ค๋ฅ˜๊ฐ€ ์•„๋‹Œ, AI ์‹œ์Šคํ…œ ์ „๋ฐ˜์˜ ์‹ ๋ขฐ์„ฑ๊ณผ ์ •์ฑ… ์ผ๊ด€์„ฑ ๋ถ•๊ดด๋กœ ์ด์–ด์งˆ ์ˆ˜ ์žˆ๋Š” ์œ„ํ—˜ ์š”์†Œ์ž…๋‹ˆ๋‹ค.

๋ถ„์„์˜ ๋ชฉ์ 

๋ณธ ๋ฐฑ์„œ์˜ ๋ชฉ์ ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค:

  1. 2024๋…„ 11์›”๋ถ€ํ„ฐ 2025๋…„ 4์›”๊นŒ์ง€ ๋ฐœํ‘œ๋œ 15ํŽธ์˜ MCP ๊ด€๋ จ ์ตœ์‹  ๋…ผ๋ฌธ์„ ์ฒด๊ณ„์ ์œผ๋กœ ๋ถ„์„ํ•˜๊ณ , ์ด๋“ค ๋ฌธํ—Œ์—์„œ ๋„์ถœ๋œ ๋ณด์•ˆ ์œ„ํ˜‘ ์‹œ๋‚˜๋ฆฌ์˜ค๋ฅผ ๋ถ„๋ฅ˜ ๋ฐ ๊ตฌ์กฐํ™”ํ•ฉ๋‹ˆ๋‹ค.
  2. MCP ๊ธฐ์ˆ ์€ 2024๋…„ 11์›” Anthropic์—์„œ ์ œ์•ˆํ•œ ๊ธฐ์ˆ ๋กœ์จ ํ˜„ ์‹œ์  ๋ฐœํ–‰๋œ ๋ชจ๋“  MCP ๋…ผ๋ฌธ์„ ๋ถ„์„ํ•˜์˜€์Šต๋‹ˆ๋‹ค.
  3. MCP ๊ธฐ๋ฐ˜์œผ๋กœ ๊ตฌ์„ฑ๋œ LLM ๋ฐ AI ์—์ด์ „ํŠธ ์‹œ์Šคํ…œ์—์„œ ์‹ค์ œ๋กœ ๋ฐœ์ƒ ๊ฐ€๋Šฅํ•œ ๊ณต๊ฒฉ ๋ฒกํ„ฐ์™€ ๋ณด์•ˆ ์ทจ์•ฝ์  ์œ ํ˜•์„ ์‹๋ณ„ํ•ฉ๋‹ˆ๋‹ค.
  4. ์ด๋Ÿฌํ•œ ์œ„ํ˜‘ ๋ถ„์„์„ ๋ฐ”ํƒ•์œผ๋กœ, ์ •์ฑ… ๊ธฐ๋ฐ˜ ๋Œ€์‘ ์ „๋žต๊ณผ ์‹ค์งˆ์ ์ธ ๊ธฐ์ˆ  ๋ณด์™„ ๋ฐฉ์•ˆ์„ ๋„์ถœํ•˜๋ฉฐ, ์ƒˆ๋กœ์šด ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜์˜ ํ•„์š”์„ฑ์„ ์ œ์–ธํ•ฉ๋‹ˆ๋‹ค.

๋ถ„์„ ๋Œ€์ƒ ๋ฌธํ—Œ ๊ตฌ์„ฑ

๋ณธ ๋ฌธํ—Œ ๋ถ„์„์€ arXiv, ResearchGate, Preprints.org, Anthropic ๋“ฑ์—์„œ ๋ฐœํ‘œ๋œ ์ด 15ํŽธ์˜ MCP ๊ด€๋ จ ์—ฐ๊ตฌ ๋ฐ ๊ธฐ์ˆ  ๋ณด๊ณ ์„œ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•˜์˜€์Šต๋‹ˆ๋‹ค. ํ•ด๋‹น ๋ฌธํ—Œ๋“ค์€ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ฃผ์ œ๋ฅผ ๋‹ค๋ฃจ๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค:

  • MCP์˜ ์•„ํ‚คํ…์ฒ˜ ๋ฐ ํ‘œ์ค€ํ™” ๋™ํ–ฅ
  • ์ •์ฑ… ๊ธฐ๋ฐ˜ ์ œ์–ด ๋ฐ ์ธ์ฆ ์œ„์ž„ ์ฒด๊ณ„
  • LLM ํ†ตํ•ฉ ์‚ฌ๋ก€ ๋ฐ ๋ฌธ๋งฅ ์ „๋‹ฌ ํ๋ฆ„
  • ๋ณด์•ˆ ์ทจ์•ฝ์ , ์ด์ƒ ํ–‰๋™, ๊ฐ์‚ฌ ๋ถˆ๊ฐ€๋Šฅ์„ฑ ๋“ฑ MCP ์‹œ์Šคํ…œ์˜ ์œ„ํ˜‘ ์‹œ๋‚˜๋ฆฌ์˜ค

๋ถ„์„ ๋Œ€์ƒ ๋…ผ๋ฌธ ์ „์ฒด๋Š” Section 2(๋ฌธํ—Œ ๋ถ„์„ ๊ฐœ์š” ๋ฐ ๋ถ„๋ฅ˜ ๊ธฐ์ค€)์˜ MCP ๊ด€๋ จ ๋ฌธํ—Œ 15ํŽธ์˜ ๋ถ„์„ ์š”์•ฝํ‘œ์— ์š”์•ฝ ์ •๋ฆฌ๋˜์–ด ์žˆ์œผ๋ฉฐ, ์ดํ›„ ๊ฐ ํŒŒํŠธ์—์„œ ์ „๋žต๋ณ„๋กœ ์—ฐ๊ณ„ํ•˜์—ฌ ์ธ์šฉ๋ฉ๋‹ˆ๋‹ค.

๋ฌธํ—Œ ๋ถ„์„์˜ ๊ธฐ์ดˆ ํ‹€

๊ฐ ๋ฌธํ—Œ์€ ๋‹ค์Œ์˜ ๋„ค ๊ฐ€์ง€ ๊ธฐ์ค€์— ๋”ฐ๋ผ ์ •๋Ÿ‰์ ยท์ •์„ฑ์ ์œผ๋กœ ๋ถ„์„ํ•˜์˜€์Šต๋‹ˆ๋‹ค:

  • ์ฃผ์š” ํ‚ค์›Œ๋“œ ๊ธฐ๋ฐ˜ ์ฃผ์ œ ๋ถ„๋ฅ˜: MCP-Security ๊ด€๋ จ ํ‚ค์›Œ๋“œ ์ค‘์‹ฌ ๋ฒ”์ฃผํ™”
  • ๋ณด์•ˆ ์œ„ํ˜‘ ์œ ํ˜• ์ค‘์‹ฌ ๊ตฌ์กฐํ™”: T1~T4์˜ ์œ„ํ˜‘ ์‹œ๋‚˜๋ฆฌ์˜ค๋กœ ๋ถ„๋ฅ˜
  • ์ถœ์ฒ˜์˜ ์‹ ๋ขฐ์„ฑยท์ตœ์‹ ์„ฑยทํ™œ์šฉ์„ฑ ํ‰๊ฐ€: ๊ณต์‹ ์—ฐ๊ตฌ ํ”Œ๋žซํผ ์œ„์ฃผ๋กœ ์ˆ˜์ง‘
  • MCP ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜์™€์˜ ์—ฐ๊ณ„์„ฑ ๊ฒ€ํ† : ์ „๋žต ๋ฐ ์ ์šฉ ๊ฐ€๋Šฅ์„ฑ ๊ธฐ์ค€์œผ๋กœ ํ‰๊ฐ€

์ด ๋ถ„์„ ํ‹€์€ ํ–ฅํ›„ Section 3(MCP ๊ธฐ๋ฐ˜ ๋ณด์•ˆ ์œ„ํ˜‘ ์‹œ๋‚˜๋ฆฌ์˜ค ๋ถ„๋ฅ˜ ๋ฐ ๋ถ„์„)๊ณผ Section 4(๊ฒฐ๋ก  ๋ฐ ์ƒˆ๋กœ์šด ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜ ์ œ์•ˆ)์—์„œ ๊ตฌ์ฒด์ ์œผ๋กœ ์ ์šฉ๋ฉ๋‹ˆ๋‹ค.

๋ฌธ์„œ ๊ตฌ์„ฑ

๋ณธ ๋ฐฑ์„œ๋Š” MCP(Model Context Protocol) ๊ธฐ๋ฐ˜ AI ์‹œ์Šคํ…œ์˜ ๋ณด์•ˆ ์œ„ํ˜‘์„ ๋ถ„์„ํ•˜๊ณ , ์ด์— ๋Œ€์‘ํ•˜๊ธฐ ์œ„ํ•œ ๊ตฌ์กฐ์  ์ „๋žต๊ณผ ์ƒˆ๋กœ์šด ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜๋ฅผ ์ œ์‹œํ•˜๊ธฐ ์œ„ํ•ด ๋‹ค์Œ๊ณผ ๊ฐ™์€ 5๊ฐœ ํŒŒํŠธ๋กœ ๊ตฌ์„ฑ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค:

1. ์„œ๋ก  ๋ฐ ๋ถ„์„ ๋ชฉ์ 

MCP๊ฐ€ ๋“ฑ์žฅํ•˜๊ฒŒ ๋œ ๋ฐฐ๊ฒฝ๊ณผ ๋ฌธ๋งฅ ๊ธฐ๋ฐ˜ ์‹œ์Šคํ…œ์—์„œ ๋ฐœ์ƒ ๊ฐ€๋Šฅํ•œ ๋ณด์•ˆ ์œ„ํ˜‘์— ๋Œ€ํ•œ ๋ฌธ์ œ ์ธ์‹์„ ์ œ์‹œํ•˜๊ณ , ์ด 15ํŽธ์˜ ์ฃผ์š” ๋ฌธํ—Œ์„ ๋ฐ”ํƒ•์œผ๋กœ ์ฒด๊ณ„์ ์ธ ์œ„ํ˜‘ ๋ถ„์„์˜ ํ•„์š”์„ฑ์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.

2. ๋ฌธํ—Œ ๋ถ„์„ ๊ฐœ์š” ๋ฐ ๋ถ„๋ฅ˜ ๊ธฐ์ค€

MCP ๊ด€๋ จ ์ตœ์‹  ๋…ผ๋ฌธ 15ํŽธ์„ ์ •๋Ÿ‰ยท์ •์„ฑ์ ์œผ๋กœ ๋ถ„๋ฅ˜ํ•˜๊ณ , T1~T4 ์œ„ํ˜‘ ์œ ํ˜•๊ณผ์˜ ์—ฐ๊ด€์„ฑ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ๋ถ„์„ํ•˜์˜€์Šต๋‹ˆ๋‹ค. ๋ถ„์„ ๊ฒฐ๊ณผ๋Š” ์ •๋ฆฌ๋œ ํ‘œ์™€ ํ•จ๊ป˜ ์ „๋žต์  ๊ธฐ์—ฌ๋„๋ฅผ ์ˆ˜์น˜ํ™”(MSR ์ ์ˆ˜)ํ•˜์—ฌ ์ œ์‹œํ•ฉ๋‹ˆ๋‹ค.

3. MCP ๊ธฐ๋ฐ˜ ๋ณด์•ˆ ์œ„ํ˜‘ ์‹œ๋‚˜๋ฆฌ์˜ค ๋ถ„๋ฅ˜ ๋ฐ ๋ถ„์„

MCP ์‹œ์Šคํ…œ ๋‚ด์—์„œ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋Š” 4๊ฐ€์ง€ ํ•ต์‹ฌ ์œ„ํ˜‘ ์œ ํ˜•(T1~T4)์— ๋Œ€ํ•ด ๊ตฌ์ฒด์ ์ธ ์‚ฌ๋ก€ ๊ธฐ๋ฐ˜ ์‹œ๋‚˜๋ฆฌ์˜ค๋ฅผ ์ œ์‹œํ•˜๊ณ , ์ฝ”๋“œ ์˜ˆ์‹œ, ์‹คํ–‰ ํ๋ฆ„, ์‹คํŒจ ํฌ์ธํŠธ๋ฅผ ํ†ตํ•ด ์œ„ํ˜‘ ๊ตฌ์กฐ๋ฅผ ์‹œ๊ฐ์ ์œผ๋กœ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.

4. ๋ถ„์„ ๊ธฐ๋ฐ˜ ์ „๋žต ์ œ์–ธ

T1~T4 ์œ„ํ˜‘์— ๋Œ€์‘ํ•˜๊ธฐ ์œ„ํ•œ 4๋Œ€ ์ „๋žต(์ •์ฑ… ์—ฐ๋™, ๋ฌธ๋งฅ ๋ฌด๊ฒฐ์„ฑ ๋ณด์žฅ, ์œ„์ž„ ํ†ต์ œ, ๊ฐ์‚ฌ ์ถ”์ ์„ฑ)์„ ์ œ์•ˆํ•˜๊ณ , ๊ฐ ์ „๋žต์ด ์ ์šฉ๋  MCP ๋ณด์•ˆ ๊ณ„์ธต๊ณผ ๊ธฐ๋Œ€ ํšจ๊ณผ๋ฅผ ๋Œ€์‘ ๋งคํ•‘ํ•˜์—ฌ ๊ตฌ์กฐํ™”ํ•ฉ๋‹ˆ๋‹ค.

5. ๊ฒฐ๋ก  ๋ฐ ์ƒˆ๋กœ์šด ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜ ์ œ์•ˆ

๊ธฐ์กด ๋Œ€์‘ ์ „๋žต์„ ๊ธฐ๋ฐ˜์œผ๋กœ, ์ด๋ฅผ ํ†ตํ•ฉยท์ž๋™ํ™”ํ•˜๊ณ  ์ž์œจ์ ์œผ๋กœ ์šด์˜ ๊ฐ€๋Šฅํ•œ ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜์ธ MCP PAM(Model Context Protocol Privileged Access Management)์„ ์ œ์•ˆํ•˜๋ฉฐ, ํ–ฅํ›„ MCP ํ™˜๊ฒฝ์—์„œ์˜ ๋ณด์•ˆ ํŒจ๋Ÿฌ๋‹ค์ž„ ์ „ํ™˜์˜ ํ•„์š”์„ฑ์„ ๊ฐ•์กฐํ•ฉ๋‹ˆ๋‹ค.

2. ๋ฌธํ—Œ ๋ถ„์„ ๊ฐœ์š” ๋ฐ ๋ถ„๋ฅ˜ ๊ธฐ์ค€

๋ถ„์„ ๋ชฉ์  ๋ฐ ์ ‘๊ทผ ๋ฐฉ์‹

๋ณธ ํŒŒํŠธ์—์„œ๋Š” MCP(Model Context Protocol) ๊ธฐ๋ฐ˜ AI ์‹œ์Šคํ…œ์—์„œ ๋ฐœ์ƒ ๊ฐ€๋Šฅํ•œ ๋ณด์•ˆ ์œ„ํ˜‘์„ ๊ตฌ์กฐ์ ์œผ๋กœ ์ดํ•ดํ•˜๊ณ  ๋Œ€์‘ํ•˜๊ธฐ ์œ„ํ•œ ๊ธฐ๋ฐ˜ ์ž๋ฃŒ๋กœ์„œ, 2024๋…„ 11์›”๋ถ€ํ„ฐ 2025๋…„ 4์›”๊นŒ์ง€ ๋ฐœํ‘œ๋œ ์ด 15ํŽธ์˜ ์ตœ์‹  ๋…ผ๋ฌธ์„ ์ˆ˜์ง‘ํ•˜๊ณ  ์ฒด๊ณ„์ ์œผ๋กœ ๋ถ„์„ํ•˜์˜€์Šต๋‹ˆ๋‹ค. ํ•ด๋‹น ๋ฌธํ—Œ๋“ค์€ arXiv, Preprints.org, ResearchGate, Anthropic ๋“ฑ์—์„œ ๋ฐœํ–‰๋œ ์—ฐ๊ตฌ ์ž๋ฃŒ๋กœ, ๋‹ค์Œ๊ณผ ๊ฐ™์€ ํ•ต์‹ฌ ์ฃผ์ œ๋ฅผ ํฌํ•จํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค:

  • MCP์˜ ๊ธฐ๋ณธ ์•„ํ‚คํ…์ฒ˜ ๋ฐ ๋ฌธ๋งฅ ๊ธฐ๋ฐ˜ ์„ค๊ณ„ ๊ตฌ์กฐ
  • ์ •์ฑ… ๊ธฐ๋ฐ˜ ์ ‘๊ทผ ์ œ์–ด์™€ ์œ„์ž„ ์ฒด๊ณ„์˜ ํ•œ๊ณ„
  • ๋ฌธ๋งฅ ํ๋ฆ„ ์ฒ˜๋ฆฌ ๋ฐ ์ „๋‹ฌ ๊ฒฝ๋กœ ์ƒ์˜ ์ทจ์•ฝ์ 
  • ๊ฐ์‚ฌ ๋กœ๊ทธ ๊ตฌ์กฐ, ๊ฐ์‚ฌ ๊ฐ€๋Šฅ์„ฑ(Auditability)์˜ ํ™•๋ณด ๋ฌธ์ œ
  • LLM ๋ฐ ์—์ด์ „ํŠธ ๊ธฐ๋ฐ˜ AI ์‹คํ–‰ ํ™˜๊ฒฝ์—์„œ์˜ ํ†ตํ•ฉ ์ •์ฑ… ์ ์šฉ ๋ฌธ์ œ

๋ณธ ๋ฌธํ—Œ ๋ถ„์„์˜ ๋ชฉ์ ์€ ๋‹จ์ˆœํ•œ ์ฃผ์ œ ์ •๋ฆฌ๋‚˜ ๊ธฐ์ˆ  ๋™ํ–ฅ ํŒŒ์•…์ด ์•„๋‹ˆ๋ผ, ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์‹ค์งˆ์ ์ธ ๋Œ€์‘๋ฐฉ์•ˆ ๊ตฌ์ถ•์— ์žˆ์Šต๋‹ˆ๋‹ค:

  • Section 3์—์„œ ์ œ์‹œํ•  T1~T4 ํ•ต์‹ฌ ์œ„ํ˜‘ ์œ ํ˜• ๋„์ถœ์— ํ•„์š”ํ•œ ์ด๋ก ์ /์‚ฌ๋ก€์  ๊ทผ๊ฑฐ ํ™•๋ณด
  • Section 4์—์„œ์˜ ์ •์ฑ… ๊ธฐ๋ฐ˜ ๋Œ€์‘ ์ „๋žต ์„ค๊ณ„ ๋ฐ ๊ณ„์ธต ๋งคํ•‘์— ํ•„์š”ํ•œ ๊ตฌ์กฐ์  ํ†ต์ฐฐ ์ œ๊ณต
  • Section 5์—์„œ ์ œ์•ˆํ•˜๋Š” MCP PAM ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜์˜ ํƒ€๋‹น์„ฑ ์ •๋ฆฝ์„ ์œ„ํ•œ ๊ธฐ๋Šฅ ๊ธฐ๋ฐ˜ ๋ถ„์„ ๊ธฐ๋ฐ˜ ํ™•๋ณด

๋”ฐ๋ผ์„œ ๋ณธ ํŒŒํŠธ์—์„œ๋Š” ๊ฐ ๋ฌธํ—Œ์„ ๊ธฐ์ˆ  ๊ธฐ์—ฌ๋„, ๋ณด์•ˆ ๊ด€๋ จ์„ฑ, ์ ์šฉ ๊ฐ€๋Šฅ์„ฑ, ์ „๋žต ์—ฐ๊ณ„์„ฑ ๋„ค ๊ฐ€์ง€ ๊ธฐ์ค€์œผ๋กœ ์ •๋Ÿ‰ยท์ •์„ฑ ํ‰๊ฐ€ํ•˜๋ฉฐ, ๊ทธ ๊ฒฐ๊ณผ๋ฅผ ํ† ๋Œ€๋กœ ๋ฌธํ—Œ ์š”์•ฝ ํ…Œ์ด๋ธ”(ํ‘œ 1) ๋ฐ ์ „๋žต ์ ํ•ฉ๋„ ์ ์ˆ˜(MSR: MCP Strategic Relevance Score)๋ฅผ ์ œ์‹œํ•ฉ๋‹ˆ๋‹ค. ์ด ๋ถ„์„ ๊ฒฐ๊ณผ๋Š” ์ดํ›„ ํŒŒํŠธ์—์„œ์˜ ๋ณด์•ˆ ์œ„ํ˜‘ ๊ตฌ์กฐํ™”, ์‹œ๋‚˜๋ฆฌ์˜ค ์„ค๊ณ„, ๋Œ€์‘ ์ „๋žต ๋„์ถœ์— ์žˆ์–ด ํ•ต์‹ฌ์ ์ธ ๊ธฐ๋ฐ˜ ์ž๋ฃŒ๋กœ ํ™œ์šฉ๋ฉ๋‹ˆ๋‹ค.

๋ถ„์„ ๊ธฐ์ค€ ๋ฐ ์ ์ˆ˜ํ™” ๋ฐฉ์‹

MCP ๊ธฐ๋ฐ˜ ๋ณด์•ˆ ์œ„ํ˜‘ ๋ถ„์„์— ํ™œ์šฉ๋œ 15ํŽธ์˜ ๋…ผ๋ฌธ์€ ๋‹จ์ˆœ ์ฃผ์ œ ๋ถ„๋ฅ˜๋ฅผ ๋„˜์–ด์„œ, ์‹ค์ œ ๋Œ€์‘ ์ „๋žต ์„ค๊ณ„์™€ ์œ„ํ˜‘ ๊ตฌ์กฐ ๋„์ถœ์— ๊ธฐ์—ฌํ•  ์ˆ˜ ์žˆ๋Š” ์ „๋žต์  ์ ํ•ฉ์„ฑ(Strategic Relevance)์„ ๊ธฐ์ค€์œผ๋กœ ์ •๋Ÿ‰ยท์ •์„ฑ ํ‰๊ฐ€ํ•˜์˜€์Šต๋‹ˆ๋‹ค.

ํ‰๊ฐ€ ํ•ญ๋ชฉ: 4๊ฐ€์ง€ ํ•ต์‹ฌ ๊ธฐ์ค€

ํ‰๊ฐ€ ๊ธฐ์ค€ ์„ค๋ช…
โ‘  ๊ธฐ์ˆ  ๊ธฐ์—ฌ๋„ (Technical Contribution)MCP ์•„ํ‚คํ…์ฒ˜ ์„ค๊ณ„, ์‹คํ–‰ ๊ตฌ์กฐ, ํ†ตํ•ฉ ๋ชจ๋ธ ๋“ฑ์— ๋Œ€ํ•œ ๊ธฐ์ˆ ์  ์ œ์•ˆ ๋ฐ ๊ตฌํ˜„ ์‚ฌ๋ก€ ํฌํ•จ ์—ฌ๋ถ€
โ‘ก ๋ณด์•ˆ ๊ด€๋ จ์„ฑ (Security Relevance)์ •์ฑ… ์œ„๋ฐ˜, ๋ฌธ๋งฅ ์กฐ์ž‘, ์œ„์ž„ ์˜ค๋‚จ์šฉ, ๊ฐ์‚ฌ ๊ฒฐํ•จ ๋“ฑ ๋ณด์•ˆ ์œ„ํ˜‘์— ๋Œ€ํ•œ ๋ช…์‹œ์  ๋ถ„์„ ํฌํ•จ ์—ฌ๋ถ€
โ‘ข ์ ์šฉ ๊ฐ€๋Šฅ์„ฑ (Applicability to MCP Systems)์ •์ฑ… ์—”์ง„, LLM ์—ฐ๋™, ์—์ด์ „ํŠธ ๊ธฐ๋ฐ˜ ์‹คํ–‰ ๋“ฑ ์‹ค์ œ ์‹œ์Šคํ…œ ์„ค๊ณ„์™€ ์—ฐ๊ณ„๋œ ํ™œ์šฉ์„ฑ ์—ฌ๋ถ€
โ‘ฃ ์ „๋žต ์—ฐ๊ณ„์„ฑ (Relevance to Strategic Design)์ด ๋ฐฑ์„œ์— ์ œ์‹œ๋œ T1โ€“T4 ์œ„ํ˜‘ ์œ ํ˜•์ด๋‚˜ MCP PAM ์ „๋žต๊ณผ ๋…ผ๋ฆฌ์ ์œผ๋กœ ์ผ์น˜ํ•˜๋Š”์ง€ ์—ฌ๋ถ€

์ „๋žต ์ ํ•ฉ๋„ ์ ์ˆ˜ (MSR) ์‚ฐ์‹

๊ฐ ๋…ผ๋ฌธ์— ๋Œ€ํ•ด์„œ๋Š” ๋‹ค์Œ์˜ 4๊ฐ€์ง€ ํ‰๊ฐ€ ํ•ญ๋ชฉ์„ ๊ธฐ์ค€์œผ๋กœ 0์ ๋ถ€ํ„ฐ 3์ ๊นŒ์ง€ ์ ์ˆ˜๋ฅผ ๋ถ€์—ฌํ•˜์˜€์œผ๋ฉฐ, ์ด๋ฅผ ๋ฐ”ํƒ•์œผ๋กœ ์ „๋žต ์ ํ•ฉ๋„ ์ ์ˆ˜(MSR: MCP Strategic Relevance Score)๋ฅผ ์•„๋ž˜์˜ ๊ฐ€์ค‘์น˜ ๊ธฐ๋ฐ˜ ์‚ฐ์‹์„ ํ†ตํ•ด ๊ณ„์‚ฐํ•˜์˜€์Šต๋‹ˆ๋‹ค:

MSRi=(Tiร—0.3)+(Siร—0.4)+(Aiร—0.2)+(Riร—0.1)MSRi=(Tiร—0.3)+(Siร—0.4)+(Aiร—0.2)+(Riร—0.1)


  • Ti (๊ธฐ์ˆ  ๊ธฐ์—ฌ๋„, Technical Contribution): MCP ์•„ํ‚คํ…์ฒ˜, ์„ค๊ณ„, ์‹คํ–‰ ๊ตฌ์กฐ ๋“ฑ์— ๋Œ€ํ•œ ๊ธฐ์ˆ ์  ์ œ์•ˆ ๋˜๋Š” ๊ตฌํ˜„ ์ˆ˜์ค€
  • Si (๋ณด์•ˆ ๊ด€๋ จ์„ฑ, Security Relevance): ์ •์ฑ… ์œ„๋ฐ˜, ๋ฌธ๋งฅ ์กฐ์ž‘, ๊ฐ์‚ฌ ๊ฒฐํ•จ ๋“ฑ ๋ณด์•ˆ ์œ„ํ˜‘ ์š”์†Œ์™€์˜ ์ง์ ‘์  ๊ด€๋ จ์„ฑ
  • Ai (์ ์šฉ ๊ฐ€๋Šฅ์„ฑ, Applicability): ์‹ค์ œ ์‹œ์Šคํ…œ์—์„œ์˜ ์‹คํ–‰ ๊ฐ€๋Šฅ์„ฑ ๋˜๋Š” ํ”„๋ ˆ์ž„์›Œํฌ ์ ์šฉ์„ฑ
  • Ri (์ „๋žต ์—ฐ๊ณ„์„ฑ, Strategic Relevance): ๋ณธ ๋ฐฑ์„œ์˜ ์œ„ํ˜‘ ์‹œ๋‚˜๋ฆฌ์˜ค(T1~T4), ๋Œ€์‘ ์ „๋žต, MCP PAM ๊ตฌ์กฐ์™€์˜ ์—ฐ๊ณ„์„ฑ

๋ถ„๋ฅ˜ ๊ธฐ์ค€

MSR ์ ์ˆ˜ ๋ฒ”์œ„ ๋ถ„๋ฅ˜ ๋ช…์นญ ์˜๋ฏธ
2.5 ์ด์ƒ์ „๋žต ํ•ต์‹ฌ ๋…ผ๋ฌธT1~T4 ์œ„ํ˜‘ ๋„์ถœ ๋ฐ MCP PAM ์ „๋žต ์ˆ˜๋ฆฝ์— ์ค‘ํ•ต์  ๊ธฐ์—ฌ ๊ฐ€๋Šฅ
1.5 ~ 2.4๋ณด์กฐ ์ธ์šฉ ๊ฐ€๋Šฅ ๋…ผ๋ฌธํŠน์ • ์ „๋žต์ด๋‚˜ ์‹œ๋‚˜๋ฆฌ์˜ค์— ๊ตญํ•œ๋œ ๋ณด์กฐ์  ๋ถ„์„ ๊ธฐ์—ฌ ๊ฐ€๋Šฅ
1.4 ์ดํ•˜๋ถ„์„ ์ œ์™ธ ๊ณ ๋ ค ๋Œ€์ƒMCP ๋ณด์•ˆ ๋งฅ๋ฝ๊ณผ์˜ ์ง์ ‘์  ์—ฐ๊ณ„์„ฑ์ด ๋‚ฎ์•„ ํ•ต์‹ฌ ๋ถ„์„์—์„œ ์ œ์™ธ๋จ

ํ™œ์šฉ ๋ชฉ์  MSR ์ ์ˆ˜์™€ ๋ถ„๋ฅ˜ ๊ธฐ์ค€์€ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋ฐฉ์‹์œผ๋กœ ํ™œ์šฉ๋ฉ๋‹ˆ๋‹ค:

  • Section 2.5์—์„œ ๋ฌธํ—Œ๋ณ„ ๋ถ„์„ ์š”์•ฝ ๋ฐ ๋ถ„๋ฅ˜ ํ…Œ์ด๋ธ” ์ž‘์„ฑ
  • Section 3์˜ T1~T4 ์œ„ํ˜‘ ์‹œ๋‚˜๋ฆฌ์˜ค ๊ตฌ์„ฑ ์‹œ ๋ฌธํ—Œ ์ธ์šฉ ์šฐ์„ ๋„ ์„ค์ •
  • Section 4 ์ „๋žต ์ œ์•ˆ์˜ ํƒ€๋‹น์„ฑ์„ ์ž…์ฆํ•  ์ˆ˜ ์žˆ๋Š” ๊ธฐ์ดˆ ๊ทผ๊ฑฐ๋กœ ํ™œ์šฉ
  • Section 5์—์„œ ์ œ์•ˆํ•˜๋Š” MCP PAM ๊ธฐ๋Šฅ์˜ ํ˜„์‹ค์„ฑ ํ™•๋ณด

๋…ผ๋ฌธ๋ณ„ ๋ถ„์„ ์ ์ˆ˜ํ‘œ (MSR)

๋ฒˆํ˜ธ์ œ๋ชฉ ์š”์•ฝTSARMSR ์ ์ˆ˜๋ถ„๋ฅ˜
1MCP ๊ตฌ์กฐ ๋ฐ ์œ„ํ˜‘ ๊ฐœ์š”32122.3๋ณด์กฐ ์ธ์šฉ
2LLM ๋ณด์•ˆ์ทจ์•ฝ์ 13232.5ํ•ต์‹ฌ ๋…ผ๋ฌธ
3์ œ์•ฝ ํ”„๋กœ๊ทธ๋ž˜๋ฐ ์—ฐ๊ณ„22322.3๋ณด์กฐ ์ธ์šฉ
4MCP ํ‘œ์ค€ํ™” ์„œ๋ฒ ์ด32122.3๋ณด์กฐ ์ธ์šฉ
5์‚ฐ์—… ํ†ตํ•ฉ ์‚ฌ๋ก€ ์ค‘์‹ฌ30101.1โŒ ๋ถ„์„ ์ œ์™ธ
6์ •์ฑ… ๊ธฐ๋ฐ˜ ์•ˆ์ „ ๋ณด์žฅ22222.2๋ณด์กฐ ์ธ์šฉ
7LLM ์—์ด์ „ํŠธ ๊ตฌ์กฐ22212.1๋ณด์กฐ ์ธ์šฉ
8ํ•˜๋“œ์›จ์–ด ํ†ตํ•ฉ ์‚ฌ๋ก€11211.4โŒ ๋ถ„์„ ์ œ์™ธ
9MCP ๊ณต์‹ ์†Œ๊ฐœ31122.1๋ณด์กฐ ์ธ์šฉ
10์ธ์ฆ ์œ„์ž„ ๋ณด์•ˆ ํ”„๋ ˆ์ž„23222.5ํ•ต์‹ฌ ๋…ผ๋ฌธ
11์ฑ…์ž„ ๋ฌธ์ œ ๋ถ„์„13132.2๋ณด์กฐ ์ธ์šฉ
12MCP ์„œ๋ฒ„ ๊ธฐ๋ฐ˜ ์ž๋™ํ™”22322.3๋ณด์กฐ ์ธ์šฉ
13์‚ฌํšŒ๊ธฐ์ˆ ์  ๋ถ„์„22132.2๋ณด์กฐ ์ธ์šฉ
14๊ธฐ์—…์šฉ MCP ์„ค๊ณ„32232.5ํ•ต์‹ฌ ๋…ผ๋ฌธ
15์ƒํ˜ธ์šด์šฉ์„ฑ๊ณผ ํ™•์žฅ์„ฑ21131.9๋ณด์กฐ ์ธ์šฉ

๋ถ„์„ ์ œ์™ธ ๋ฌธํ—Œ ์„ค๋ช…

๋‹ค์Œ ๋ฌธํ—Œ์€ ์ „๋žต ์ ํ•ฉ๋„(MSR)๊ฐ€ ๋‚ฎ์•„ ๋ณด์•ˆ ์œ„ํ˜‘ ๋ถ„์„ ๋ฒ”์œ„์—์„œ ์ œ์™ธํ•˜์˜€์Šต๋‹ˆ๋‹ค:

  • [5] Paul Pajo, โ€œSmithery.aiโ€ฆโ€: ๋ณด์•ˆ์ด ์•„๋‹Œ ์‚ฐ์—… ํ†ตํ•ฉ ์‚ฌ๋ก€ ์ค‘์‹ฌ. ๋ณด์•ˆ ์œ„ํ˜‘ ๊ตฌ์กฐ์™€์˜ ์—ฐ๊ฒฐ ๋ฏธ์•ฝ.
  • [8] Xinyi Hou, โ€œHardware Synergyโ€ฆโ€: ํ•˜๋“œ์›จ์–ด ์—ฐ๊ณ„ ๊ธฐ์ˆ ์— ์น˜์šฐ์ณ ๋ณด์•ˆ ๊ตฌ์กฐ ๋ถ„์„๊ณผ ์ง์ ‘ ์—ฐ๊ณ„ ์–ด๋ ค์›€.

ํ•ด๋‹น ๋…ผ๋ฌธ๋“ค์€ ์ฐธ๊ณ ์ž๋ฃŒ๋กœ๋Š” ์œ ํšจํ•˜๋‚˜, ์œ„ํ˜‘ ์‹œ๋‚˜๋ฆฌ์˜ค ๋„์ถœ์—๋Š” ๋ถ€์ ํ•ฉํ•˜๋‹ค๊ณ  ํŒ๋‹จํ•˜์˜€์Šต๋‹ˆ๋‹ค.

๋ฌธํ—Œ ์š”์•ฝ ํ…Œ์ด๋ธ” ์•ˆ๋‚ด

๋‹ค์Œ ํ‘œ๋Š” ๋ถ„์„ ๋Œ€์ƒ ๋…ผ๋ฌธ 15ํŽธ์˜ ์ฃผ์š” ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์™€ ์ดˆ๋ก์„ ์š”์•ฝํ•œ ์ •๋ฆฌ์ž…๋‹ˆ๋‹ค. ๊ฐ ๋…ผ๋ฌธ์€ ์ดํ›„ ํŒŒํŠธ์—์„œ T1~T4 ์œ„ํ˜‘ ์œ ํ˜•, ์ „๋žต ๋Œ€์‘ ๊ตฌ์กฐ, ์ •์ฑ… ํ”„๋ ˆ์ž„ ์„ค๊ณ„์˜ ๊ทผ๊ฑฐ๋กœ ์ธ์šฉ๋ฉ๋‹ˆ๋‹ค.

๊ฐ ๋ฌธํ—Œ์€ ๋‹ค์Œ ์ •๋ณด๋ฅผ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค:

  • ๋ฐœํ‘œ ์‹œ์ 
  • ์ €์ž
  • ๋…ผ๋ฌธ ์ œ๋ชฉ ๋ฐ ํ•ต์‹ฌ ์ฃผ์ œ
  • ์ดˆ๋ก ์š”์•ฝ
  • ์ฃผ์š” ํ‚ค์›Œ๋“œ
  • ์ถœ์ฒ˜ ํ”Œ๋žซํผ
  • ์ง์ ‘ ๋‹ค์šด๋กœ๋“œ ๊ฐ€๋Šฅํ•œ ๋งํฌ

MCP ๊ด€๋ จ ๋ฌธํ—Œ 15ํŽธ์˜ ๋ถ„์„ ์š”์•ฝํ‘œ (2024.11 ~ 2025.04.11)

No.DateAuthor(s)Paper TitleAbstract SummaryKeywordsSource
1Mar 2025Xinyi Hou et al.Model Context Protocol (MCP): Landscape, Security Threats, and Future Research DirectionsMCP์˜ ์•„ํ‚คํ…์ฒ˜์™€ ๋ณด์•ˆ ์œ„ํ—˜์„ ๋ถ„์„ํ•˜๊ณ , ๋„์ž… ์‹œ ๋ฐœ์ƒํ•˜๋Š” ๊ณผ์ œ ๋ฐ ํ–ฅํ›„ ์—ฐ๊ตฌ ๋ฐฉํ–ฅ์„ ์ œ์‹œํ•จ.MCP, SecurityarXiv
2Apr 2025Brandon Radosevich, John HalloranMCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security ExploitsMCP๊ฐ€ ์ ์šฉ๋œ LLM์—์„œ ๋ฐœ์ƒ ๊ฐ€๋Šฅํ•œ ์ฃผ์š” ๋ณด์•ˆ ์ทจ์•ฝ์ ์„ ์‹๋ณ„ํ•˜๊ณ  ์ด๋ฅผ ์ ๊ฒ€ํ•˜๊ธฐ ์œ„ํ•œ ๊ฐ์‚ฌ ๋ฐฉ๋ฒ•์„ ์ œ์•ˆํ•จ.MCP, SecurityarXiv
3Apr 2025Stefan SzeiderMCP-Solver: Integrating Language Models with Constraint Programming SystemsLLM๊ณผ ์ œ์•ฝ ์กฐ๊ฑด ํ•ด๊ฒฐ๊ธฐ๋ฅผ MCP๋ฅผ ํ†ตํ•ด ํ†ตํ•ฉํ•˜์—ฌ ๋ฌธ์ œ ํ•ด๊ฒฐ ์„ฑ๋Šฅ์„ ํ–ฅ์ƒ์‹œํ‚ค๋Š” ๋ฐฉ์•ˆ์„ ์†Œ๊ฐœํ•จ.MCP, Constraint SolvingarXiv
4Apr 2025Aditi Singh et al.A Survey of the Model Context Protocol (MCP): Standardizing Context to Enhance Large Language Models (LLMs)์‚ฐ์—… ์ „๋ฐ˜์—์„œ LLM์˜ ๋ฌธ๋งฅ ๊ด€๋ฆฌ๋ฅผ ํ‘œ์ค€ํ™”ํ•˜๊ธฐ ์œ„ํ•œ MCP์˜ ์ž ์žฌ๋ ฅ๊ณผ ๋ฐฉํ–ฅ์„ฑ์„ ์ข…ํ•ฉ์ ์œผ๋กœ ๊ฒ€ํ† ํ•จ.MCP, LLM IntegrationPreprints.org
5Mar 2025Paul PajoSmithery.ai: A Model Context Protocol for Enhanced LLM Integration and Cross-Industry ApplicationsMCP ๊ธฐ๋ฐ˜ ํ”„๋ ˆ์ž„์›Œํฌ๋ฅผ ํ™œ์šฉํ•œ ์‚ฐ์—… ์ „๋ฐ˜์˜ LLM ํ†ตํ•ฉ ์‚ฌ๋ก€ ๋ฐ ๊ฐ€๋Šฅ์„ฑ์„ ์„ค๋ช…ํ•จ.MCP, LLM IntegrationResearchGate
6Mar 2025Zhaorun Chen et al.ShieldAgent: Shielding Agents via Verifiable Safety Policy ReasoningMCP ๋‚ด์—์„œ AI ์—์ด์ „ํŠธ๋ฅผ ๋ณดํ˜ธํ•˜๊ธฐ ์œ„ํ•œ ๊ฒ€์ฆ ๊ฐ€๋Šฅํ•œ ์•ˆ์ „ ์ •์ฑ…์„ ์ œ์•ˆํ•˜๊ณ  ๊ทธ ํšจ๊ณผ๋ฅผ ๋ถ„์„ํ•จ.MCP, SafetyarXiv
7Mar 2025Junyu Luo et al.Large Language Model Agent: A Survey on Methodology, Applications and ChallengesMCP๋ฅผ ํ™œ์šฉํ•œ LLM ๊ธฐ๋ฐ˜ ์—์ด์ „ํŠธ์˜ ๋ฐฉ๋ฒ•๋ก , ์‘์šฉ ์‚ฌ๋ก€, ๋„์ „ ๊ณผ์ œ ๋“ฑ์„ ํฌ๊ด„์ ์œผ๋กœ ์กฐ์‚ฌํ•จ.MCP, LLM AgentsarXiv
8Mar 2025Xinyi Hou et al.The Next Frontier of LLM Applications: Open Ecosystems and Hardware SynergyMCP ๊ธฐ๋ฐ˜ LLM ์ƒํƒœ๊ณ„์—์„œ์˜ ํ•˜๋“œ์›จ์–ด ํ†ตํ•ฉ ๋ฐ ๊ฐœ๋ฐฉํ˜• ์ƒํƒœ๊ณ„ ๊ตฌ์ถ• ๋ฐฉ์•ˆ์„ ํƒ์ƒ‰ํ•จ.MCP, Hardware IntegrationarXiv
9Nov 2024AnthropicIntroducing the Model Context ProtocolLLM์—์„œ ๋ฌธ๋งฅ ํ†ตํ•ฉ์„ ์œ„ํ•œ ํ‘œ์ค€์œผ๋กœ์„œ MCP๋ฅผ ๊ณต์‹์ ์œผ๋กœ ์†Œ๊ฐœํ•˜๊ณ  ๊ทธ ํ•ต์‹ฌ ๊ฐœ๋…์„ ์„ค๋ช…ํ•จ.MCP, IntegrationAnthropic
10Jan 2025Tobin South et al.Authenticated Delegation and Authorized AI AgentsMCP๋ฅผ ํ™œ์šฉํ•œ ๋ณด์•ˆ ์—์ด์ „ํŠธ ์œ„์ž„ ๋ฐ ๊ถŒํ•œ ๋ถ€์—ฌ ์ฒด๊ณ„๋ฅผ ์ œ์•ˆํ•จ.MCP, AI AgentsarXiv
11Apr 2025Garry A. Gabison, R. Patrick XianInherent and Emergent Liability Issues in LLM-Based Agentic SystemsMCP ๊ธฐ๋ฐ˜ LLM ์—์ด์ „ํŠธ ์‹œ์Šคํ…œ์—์„œ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋Š” ๋ฒ•์  ์ฑ…์ž„ ๋ฌธ์ œ๋ฅผ ๋ถ„์„ํ•˜๊ณ  ๊ณ ์ฐฐํ•จ.MCP, LiabilityarXiv
12Mar 2025Paul PajoModel Context Protocol Servers: A Novel Paradigm for AI-Driven Workflow Automation๊ธฐ์กด ์‹œ์Šคํ…œ๊ณผ ๋น„๊ตํ•˜์—ฌ MCP ์„œ๋ฒ„๋ฅผ ํ†ตํ•œ AI ๊ธฐ๋ฐ˜ ์›Œํฌํ”Œ๋กœ์šฐ ์ž๋™ํ™”์˜ ํšจ๊ณผ๋ฅผ ํ‰๊ฐ€ํ•จ.MCP Servers, AutomationResearchGate
13Mar 2025Paul PajoAccelerating AI Integration: Multi-Order Effects and Sociotechnical Implications of Standardized AI-Tool InteroperabilityMCP ํ‘œ์ค€ํ™”๊ฐ€ AI ํ†ตํ•ฉ์— ๋ฏธ์น˜๋Š” ๋‹ค๊ณ„์ธต์  ์˜ํ–ฅ๊ณผ ์‚ฌํšŒ๊ธฐ์ˆ ์  ํ•จ์˜๋ฅผ ๋ถ„์„ํ•จ.MCP, InteroperabilityResearchGate
14Mar 2025Anand RamachandranTransforming Enterprise AI Integration: Architecture, Implementation and Applications of MCP๊ธฐ์—… ๋‚ด AI ํ†ตํ•ฉ์„ ์œ„ํ•œ MCP ๊ธฐ๋ฐ˜ ์•„ํ‚คํ…์ฒ˜ ์„ค๊ณ„, ๊ตฌํ˜„ ์‚ฌ๋ก€ ๋ฐ ์ ์šฉ ๋ฐฉ์•ˆ์„ ๊ณ ์ฐฐํ•จ.MCP, Enterprise AIResearchGate
15Mar 2025Ashish KattamuriUnlocking Context for Intelligent Agents: The Model Context Protocol as a Standardized Integration Frameworkํ‘œ์ค€ํ™”๋œ AI ๋„๊ตฌ ์ƒํ˜ธ์šด์šฉ์„ฑ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•œ MCP์˜ ์‚ฌํšŒ๊ธฐ์ˆ ์  ํŒŒ๊ธ‰ ํšจ๊ณผ๋ฅผ ๋…ผ์˜ํ•จ.MCP, LLM Integration, StandardizationIJIRSET

3. MCP ๊ธฐ๋ฐ˜ ๋ณด์•ˆ ์œ„ํ˜‘ ์‹œ๋‚˜๋ฆฌ์˜ค ๋ถ„๋ฅ˜ ๋ฐ ๋ถ„์„

๋ถ„์„ ์ ‘๊ทผ ๋ฐฉ์‹

์•ž์„  Section 2์—์„œ ์ œ์‹œํ•œ 15ํŽธ์˜ ๋ฌธํ—Œ ๋ถ„์„์„ ๊ธฐ๋ฐ˜์œผ๋กœ, ๋ณธ ํŒŒํŠธ์—์„œ๋Š” MCP(Model Context Protocol) ๊ธฐ๋ฐ˜ AI ์‹œ์Šคํ…œ์—์„œ ๋ฐœ์ƒ ๊ฐ€๋Šฅํ•œ ๋ณด์•ˆ ์œ„ํ˜‘ ์œ ํ˜•(Security Threat Types)์„ ๊ตฌ์กฐ์ ์œผ๋กœ ๋ถ„๋ฅ˜ํ•˜๊ณ  ์‹ค์ œ ์‹œ๋‚˜๋ฆฌ์˜ค๋กœ ํ™•์žฅํ•˜์—ฌ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค. MCP๋Š” AI ๋ชจ๋ธ ๊ฐ„์˜ ๋ฌธ๋งฅ(Context) ๋ฐ ์ •์ฑ…(Policy) ๊ตํ™˜์„ ์ง€์›ํ•˜๋Š” ํ•ต์‹ฌ ํ”„๋กœํ† ์ฝœ๋กœ ์„ค๊ณ„๋˜์—ˆ์ง€๋งŒ, ๊ทธ ๊ตฌ์กฐ์  ํŠน์„ฑ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋ณด์•ˆ ์œ„ํ˜‘ ๋ชจ๋ธ์„ ๋””์ž์ธ ํ• ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

MCP ๋ณด์•ˆ ์œ„ํ˜‘ ์œ ํ˜• ๋ถ„๋ฅ˜

์œ ํ˜•์œ„ํ˜‘๋ช… (์˜๋ฌธ ๋ณ‘๊ธฐ)์„ค๋ช…์ฃผ์š” ๋ฌธํ—Œ ์ถœ์ฒ˜
T1๋ฌธ๋งฅ ์กฐ์ž‘ (Context Injection / Spoofing)๊ณต๊ฒฉ์ž๊ฐ€ ์œ„์กฐ๋œ ๋ฌธ๋งฅ์„ ์ฃผ์ž…ํ•˜๊ฑฐ๋‚˜ ๊ธฐ์กด ๋ฌธ๋งฅ์„ ๋ณ€๊ฒฝํ•˜์—ฌ LLM ๋˜๋Š” ์—์ด์ „ํŠธ์˜ ํ–‰์œ„๋ฅผ ์™œ๊ณกํ•จ[1], [2], [10]
T2๊ถŒํ•œ ์œ„์ž„ ์˜ค์šฉ (Delegation Abuse)๊ณผ๋„ํ•œ ์ธ์ฆ ์œ„์ž„ ๋˜๋Š” ์ธ์ฆ ์ฒด๊ณ„์˜ ๋ฏธ๋น„๋กœ ์ธํ•ด ๋น„์ธ๊ฐ€๋œ ์—์ด์ „ํŠธ๊ฐ€ ๊ณ ๊ถŒํ•œ ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•จ[2], [10], [11], [14]
T3๋ชจ๋ธ ์˜ค์ž‘๋™ ์œ ๋„ (Model Misbehavior via Exploitable Context)๋น„์ •์ƒ์  ๋ฌธ๋งฅ ๊ตฌ์กฐ๋ฅผ ํ†ตํ•ด AI ๋ชจ๋ธ์˜ ๋น„์˜๋„์  ๋˜๋Š” ๋น„์œค๋ฆฌ์  ์ถœ๋ ฅ์„ ์œ ๋„ํ•จ[1], [6], [7]
T4๊ฐ์‚ฌ ๋ถˆ๊ฐ€๋Šฅ์„ฑ (Non-auditable Context Flow)๋ฌธ๋งฅ์˜ ์ „๋‹ฌ ๊ฒฝ๋กœ๊ฐ€ ๊ธฐ๋ก๋˜์ง€ ์•Š๊ฑฐ๋‚˜ ํ‘œ์ค€ํ™”๋˜์ง€ ์•Š์•„ ๋ณด์•ˆ ๊ฐ์‹œ ๋ฐ ์‚ฌ๊ณ  ๋Œ€์‘์ด ์–ด๋ ค์›€[2], [12], [13]

์ฃผ์š” ์œ„ํ˜‘ ์‹œ๋‚˜๋ฆฌ์˜ค

์‹œ๋‚˜๋ฆฌ์˜ค A: ๋ฌธ๋งฅ ์ฃผ์ž…์„ ํ†ตํ•œ LLM ์˜ค์ž‘๋™ ์œ ๋„ (T1, T3)

MCP(Model Context Protocol)๋Š” ๋ฌธ๋งฅ(Context)์„ ๊ตฌ์กฐํ™”ํ•˜์—ฌ LLM์ด๋‚˜ AI ์—์ด์ „ํŠธ๊ฐ€ ์ •ํ™•ํ•œ ์‹คํ–‰ ํ™˜๊ฒฝ์—์„œ ์ž‘๋™ํ•˜๋„๋ก ๋ณด์žฅํ•˜๋Š” ์—ญํ• ์„ ํ•ฉ๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ์ด ๋ฌธ๋งฅ ์ •๋ณด๊ฐ€ ๊ฒ€์ฆ ์—†์ด ์™ธ๋ถ€๋กœ๋ถ€ํ„ฐ ์ฃผ์ž…๋˜๊ฑฐ๋‚˜, ์ „๋‹ฌ ์ค‘ ์กฐ์ž‘๋  ๊ฒฝ์šฐ, LLM์€ ๊ณต๊ฒฉ์ž์˜ ์˜๋„๋Œ€๋กœ ์˜ค์ž‘๋™ํ•˜๋ฉฐ ๋น„์ธ๊ฐ€๋œ ์‘๋‹ต, ๊ถŒํ•œ ์˜ค์šฉ, ์‹œ์Šคํ…œ ์™œ๊ณก์„ ์œ ๋ฐœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” ๋‹จ์ˆœํ•œ prompt injection๊ณผ๋Š” ์ฐจ์›์ด ๋‹ค๋ฅธ ํ”„๋กœํ† ์ฝœ ๊ณ„์ธต์˜ ๋ฌธ๋งฅ ์˜ค์—ผ ๊ณต๊ฒฉ(Context-level Protocol Tampering)์ž…๋‹ˆ๋‹ค.


์œ„ํ˜‘ ํ๋ฆ„ ์˜ˆ์‹œ:

  1. ์‚ฌ์šฉ์ž๋Š” LLM์—๊ฒŒ โ€œ๋‚ด ๊ณ„์ขŒ ์ž”์•ก์„ ํ™•์ธํ•ด์ค˜โ€๋ผ๋Š” ์š”์ฒญ์„ ๋ณด๋ƒ…๋‹ˆ๋‹ค.
  2. ์‹œ์Šคํ…œ์€ Context Payload ๋ฅผ ์ƒ์„ฑํ•˜๋ฉฐ, ์‚ฌ์šฉ์ž์˜ ๊ถŒํ•œ ์ •๋ณด๋ฅผ ํฌํ•จํ•˜์—ฌ LLM์—๊ฒŒ ์ „๋‹ฌํ•ฉ๋‹ˆ๋‹ค.
  3. ๊ณต๊ฒฉ์ž๋Š” ์ค‘๊ฐ„ ๋…ธ๋“œ ํ˜น์€ ์ทจ์•ฝํ•œ ์—์ด์ „ํŠธ๋ฅผ ์žฅ์•…ํ•˜์—ฌ Context Payload๋ฅผ ์กฐ์ž‘ํ•ฉ๋‹ˆ๋‹ค.
  4. LLM์€ ๋ณ€์กฐ๋œ ๋ฌธ๋งฅ์„ ์‹ ๋ขฐํ•˜๊ณ , ์‚ฌ์šฉ์ž์—๊ฒŒ ํ—ˆ์šฉ๋˜์ง€ ์•Š์€ ๋ช…๋ น(์˜ˆ: ์†ก๊ธˆ, ๊ณ„์ขŒ ์‚ญ์ œ)์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.
  5. ์‹œ์Šคํ…œ์€ ํ•ด๋‹น ์‘๋‹ต์„ ๊ฒ€์ฆํ•˜์ง€ ๋ชปํ•˜๊ณ  ๊ทธ๋Œ€๋กœ ์‹คํ–‰ํ•˜๊ฒŒ ๋˜์–ด, ๊ถŒํ•œ ์ƒ์Šน(Privilege Escalation) ๋˜๋Š” ๊ธฐ๋ฐ€ ๋ฐ์ดํ„ฐ ์œ ์ถœ๋กœ ์ด์–ด์ง‘๋‹ˆ๋‹ค.

์ฝ”๋“œ ์˜ˆ์‹œ: ๋ฌธ๋งฅ ์กฐ์ž‘ ์ „ํ›„ ๋น„๊ต

// ์ •์ƒ Context Payload
{
    "user": {
        "id": "user_84321",
        "role": "viewer",
        "authenticated": true
    },
    "request": {
        "action": "view_balance"
    },
    "policy": {
        "allow": ["view_balance"],
        "deny": ["transfer_funds", "delete_account"]
    }
}
// ๊ณต๊ฒฉ์ž๊ฐ€ ์ฃผ์ž…ํ•œ ์กฐ์ž‘๋œ Context Payload
{
    "user": {
        "id": "user_84321",
        "role": "admin",   // ๊ถŒํ•œ ์œ„์žฅ
        "authenticated": true
    },
    "request": {
        "action": "transfer_funds"   // ๊ณ ์œ„ํ—˜ ์ž‘์—… ๋ณ€๊ฒฝ
    },
    "policy": {
        "allow": ["view_balance", "transfer_funds"],
        "deny": []
    }
}

์œ„ ์กฐ์ž‘๋œ ๋ฌธ๋งฅ์€ ์‹œ์Šคํ…œ ๋‚ด๋ถ€์—์„œ ์ •์ƒ ์‚ฌ์šฉ์ž์— ์˜ํ•œ ๊ด€๋ฆฌ์ž ๊ถŒํ•œ ์š”์ฒญ์œผ๋กœ ์˜ค์ธ๋˜์–ด, LLM์ด ํŠน์ˆ˜๊ถŒํ•œ ๋ช…๋ น์„ ๊ทธ๋Œ€๋กœ ์ฒ˜๋ฆฌํ•˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.


๋ณด์•ˆ ์‹คํŒจ ํฌ์ธํŠธ

  • ๋ฌธ๋งฅ์˜ ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์ฆ ๋ฏธ๋น„

Context Payload์˜ ์ฃผ์š” ํ•„๋“œ(role, action, policy)์— ๋Œ€ํ•œ ์„œ๋ช… ๋˜๋Š” ์ธ์ฆ ๊ธฐ๋Šฅ์ด ์—†์Šต๋‹ˆ๋‹ค.

  • ์ •์ฑ… ์ •๋ณด๊ฐ€ ํด๋ผ์ด์–ธํŠธ ์ธก์—์„œ ์ฃผ์ž… ๊ฐ€๋Šฅ

์ •์ฑ…(allow/deny) ์ •๋ณด๊ฐ€ ์„œ๋ฒ„๊ฐ€ ์•„๋‹Œ ํด๋ผ์ด์–ธํŠธ ๋˜๋Š” ์ค‘๊ฐ„ ๋…ธ๋“œ์—์„œ ์ƒ์„ฑ๋˜์–ด ์‹ ๋ขฐ์„ฑ์„ ํ™•๋ณดํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

  • LLM์ด ๋ฌธ๋งฅ ๊ธฐ๋ฐ˜ ์˜์‚ฌ๊ฒฐ์ •์„ ๋…๋ฆฝ์ ์œผ๋กœ ์ˆ˜ํ–‰

LLM ์ž์ฒด๊ฐ€ context์— ๋Œ€ํ•ด ์ถ”๊ฐ€ ๊ฒ€์ฆ ์—†์ด ์‹คํ–‰ ๊ฒฐ์ •์„ ๋‚ด๋ฆฌ๋Š” ๊ตฌ์กฐ๋กœ ์„ค๊ณ„๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

  • Context ๊ตฌ์กฐ์™€ ์ •์ฑ… ๊ฒ€์ฆ ๋กœ์ง์˜ ๋ถ„๋ฆฌ

Context๋ฅผ ์ƒ์„ฑํ•˜๋Š” ๊ณ„์ธต๊ณผ ์ด๋ฅผ ๊ฒ€์ฆํ•˜๊ณ  ์ ์šฉํ•˜๋Š” ๊ณ„์ธต์ด ์„œ๋กœ ๋ถ„๋ฆฌ๋˜์–ด ๊ณต๊ฒฉ ๊ฒฝ๋กœ๊ฐ€ ๊ฐœ๋ฐฉ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.


์‹œ๋‚˜๋ฆฌ์˜ค B: ๋น„์ธ๊ฐ€ ์—์ด์ „ํŠธ์˜ ๊ถŒํ•œ ์œ„์ž„ ์‚ฌ์นญ (T2)

MCP ๊ธฐ๋ฐ˜ ์‹œ์Šคํ…œ์—์„œ ์—์ด์ „ํŠธ ๊ฐ„์˜ ํ˜‘์—…์€ ์ •์ฑ… ๊ธฐ๋ฐ˜ ์œ„์ž„ ๊ตฌ์กฐ(Policy-based Delegation)๋ฅผ ํ†ตํ•ด ์ด๋ฃจ์–ด์ง‘๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์œ„์ž„ ์š”์ฒญ(Delegation Request)์˜ ์œ ํšจ์„ฑ ๊ฒ€์ฆ ์ ˆ์ฐจ๊ฐ€ ๋ถ€์กฑํ•˜๊ฑฐ๋‚˜ ์œ„์ž„ ์ฒด์ธ ์ถ”์ ์ด ๋ถˆ์™„์ „ํ•œ ๊ฒฝ์šฐ, ๊ณต๊ฒฉ์ž๋Š” ํ•˜์œ„ ์—์ด์ „ํŠธ๋ฅผ ์žฅ์•…ํ•œ ๋’ค ๊ณ ๊ถŒํ•œ ์—์ด์ „ํŠธ๋ฅผ ์‚ฌ์นญํ•˜์—ฌ ์œ„์ž„ ๊ถŒํ•œ์„ ํƒˆ์ทจํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” ๋น„์ธ๊ฐ€ ๊ถŒํ•œ ์ƒ์Šน(Unauthorized Privilege Escalation)์„ ์•ผ๊ธฐํ•˜๋ฉฐ, ์‹œ์Šคํ…œ ์ „๋ฐ˜์˜ ๋ฌด๊ฒฐ์„ฑ์„ ์œ„ํ˜‘ํ•ฉ๋‹ˆ๋‹ค.


์œ„ํ˜‘ ํ๋ฆ„ ์˜ˆ์‹œ:

  1. ์—์ด์ „ํŠธ A๋Š” ํ•ต์‹ฌ ์ธํ”„๋ผ ๊ด€๋ฆฌ ๊ถŒํ•œ์„ ๊ฐ€์ง„ ์ƒ์œ„ ์—์ด์ „ํŠธ์ž…๋‹ˆ๋‹ค.
  2. ์—์ด์ „ํŠธ B๋Š” ์™ธ๋ถ€ ์—ฐ๋™์šฉ ๋˜๋Š” ๊ณ ๊ฐ ์‘๋Œ€ ์ „์šฉ์œผ๋กœ ์„ค๊ณ„๋œ ์ œํ•œ๋œ ๊ถŒํ•œ์˜ ํ•˜์œ„ ์—์ด์ „ํŠธ์ž…๋‹ˆ๋‹ค.
  3. ๊ณต๊ฒฉ์ž๋Š” B๋ฅผ ๋จผ์ € ์žฅ์•…ํ•œ ํ›„, A์—๊ฒŒ์„œ ์œ„์ž„๋ฐ›์€ ๊ฒƒ์ฒ˜๋Ÿผ ์กฐ์ž‘๋œ Delegation Payload๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.
  4. ์‹œ์Šคํ…œ์€ from_agent, token, scope ํ•„๋“œ์˜ ์œ„์กฐ ์—ฌ๋ถ€๋ฅผ ๊ฒ€์ฆํ•˜์ง€ ์•Š๊ณ  ์š”์ฒญ์„ ์ˆ˜๋ฝํ•ฉ๋‹ˆ๋‹ค.
  5. ๊ทธ ๊ฒฐ๊ณผ, ๊ณต๊ฒฉ์ž๋Š” B๊ฐ€ A์˜ ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋˜๋Š” ๊ถŒํ•œ ์šฐํšŒ(Boundary Bypass)๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

์ฝ”๋“œ ์˜ˆ์‹œ: ์œ„์ž„ ์š”์ฒญ ์‚ฌ์นญ ๊ณต๊ฒฉ

// ์ •์ƒ์ ์ธ ์œ„์ž„ ์š”์ฒญ ๊ตฌ์กฐ
{
    "type": "delegation_request",
    "from_agent": "agent_b",
    "to_agent": "agent_a",
    "scope": "read_only",
    "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
}
// ๊ณต๊ฒฉ์ž๊ฐ€ ์กฐ์ž‘ํ•œ ์œ„์ž„ ์š”์ฒญ
{
    "type": "delegation_request",
    "from_agent": "agent_a",             // ์œ„์กฐ๋œ ์ถœ๋ฐœ ์ฃผ์ฒด
    "to_agent": "agent_b",
    "scope": "infrastructure_control",   // ์ƒ์œ„ ๊ถŒํ•œ ์š”์ฒญ
    "token": "eyJhbGciOiJI...TamperedToken..."  // ๋ณ€์กฐ๋œ ์„œ๋ช… ์—†๋Š” ํ† ํฐ
}

์œ„ ์š”์ฒญ์€ ์‹œ์Šคํ…œ ๋‚ด์—์„œ ๊ฒ€์ฆ ์ ˆ์ฐจ ์—†์ด ์ฒ˜๋ฆฌ๋  ๊ฒฝ์šฐ, ์—์ด์ „ํŠธ B๊ฐ€ ์—์ด์ „ํŠธ A์˜ ๊ณ ์œ ํ•œ ๊ถŒํ•œ์œผ๋กœ ์‹œ์Šคํ…œ ์„ค์ • ๋ณ€๊ฒฝ, ํŒŒ์ผ ์‚ญ์ œ, ์‚ฌ์šฉ์ž ๊ณ„์ • ์ˆ˜์ • ๋“ฑ ๊ณ ์œ„ํ—˜ ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.


๋ณด์•ˆ ์‹คํŒจ ํฌ์ธํŠธ

  • ์œ„์ž„ ์š”์ฒญ์˜ ์‹ ์› ์ธ์ฆ ๋ฏธ๋น„

from_agent ํ•„๋“œ์˜ ์†Œ์Šค๊ฐ€ ์‹ค์ œ ํ•ด๋‹น ์—์ด์ „ํŠธ์—์„œ ๋ฐœ๊ธ‰๋˜์—ˆ๋Š”์ง€ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋Š” ์„œ๋ช… ๋˜๋Š” ์ธ์ฆ ์ฒด๊ณ„๊ฐ€ ๋ถ€์žฌํ•ฉ๋‹ˆ๋‹ค.

  • ์œ„์ž„ ๋ฒ”์œ„ ์ œํ•œ ๋ฏธ๊ตฌํ˜„

scope ํ•„๋“œ์— ๋Œ€ํ•œ ์ •์ฑ…์  ์ƒํ•œ ๋˜๋Š” ์œ ํšจ ๋ฒ”์œ„๋ฅผ ๊ฒ€์ฆํ•˜์ง€ ์•Š์•„ ๊ณผ๋„ํ•œ ๊ถŒํ•œ์ด ํ—ˆ์šฉ๋ฉ๋‹ˆ๋‹ค.

  • ์œ„์ž„ ์ฒด์ธ ์ถ”์  ๋ถˆ๊ฐ€

์œ„์ž„์˜ ๊ณ„์Šน ๊ฒฝ๋กœ๋‚˜ ์‹ ๋ขฐ ์ฒด์ธ์„ ์ถ”์ ํ•  ์ˆ˜ ์—†์–ด ์ด์ค‘ ์œ„์ž„, ์‚ฌ์นญ ์œ„์ž„ ๋“ฑ์„ ํƒ์ง€ํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

  • ์„œ๋ช… ๊ฒ€์ฆ ์—†์ด ์ˆ˜์šฉ๋˜๋Š” ํ† ํฐ

JWT, MAC ๊ธฐ๋ฐ˜ ํ† ํฐ์ด ์„œ๋ช… ๋˜๋Š” ํƒ€์ž„์Šคํƒฌํ”„ ์—†์ด ์ˆ˜์šฉ๋˜๋Š” ๊ตฌ์กฐ๋Š” ๋ณ€์กฐ ๋ฐ ์žฌ์‚ฌ์šฉ ๊ณต๊ฒฉ์— ์ทจ์•ฝํ•ฉ๋‹ˆ๋‹ค.


์‹œ๋‚˜๋ฆฌ์˜ค C: ๋™์ผ ๋ฌธ๋งฅ์˜ ์‹คํ–‰ ํ™˜๊ฒฝ ๊ฐ„ ๊ฒฐ๊ณผ ํŽธ์ฐจ (T3)

MCP๋Š” ๋™์ผํ•œ ๋ฌธ๋งฅ(Context)์„ ์—ฌ๋Ÿฌ ์‹คํ–‰ ํ™˜๊ฒฝ์— ์ „๋‹ฌํ•˜์—ฌ ์ผ๊ด€๋œ ์ •์ฑ… ์ ์šฉ(Policy Consistency)๊ณผ ์˜ˆ์ธก ๊ฐ€๋Šฅํ•œ ์‹œ์Šคํ…œ ๋™์ž‘(Security Predictability)์„ ๋ณด์žฅํ•˜๊ณ ์ž ํ•ฉ๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ์‹ค์ œ ํ™˜๊ฒฝ์—์„œ๋Š” LLM ๋˜๋Š” ์—์ด์ „ํŠธ์˜ ๊ตฌ์„ฑ, ์ง€์—ญ ์ •์ฑ… ๋กœ๋”ฉ ๋ฐฉ์‹, ํ•ด์„๊ธฐ์˜ ๋ฒ„์ „ ์ฐจ์ด ๋“ฑ์œผ๋กœ ์ธํ•ด ๋™์ผํ•œ Context๊ฐ€ ์‹คํ–‰ ์œ„์น˜์— ๋”ฐ๋ผ ๋‹ค๋ฅด๊ฒŒ ํ•ด์„๋˜๋Š” ๋น„๊ฒฐ์ •์„ฑ(Non-determinism) ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์ฐจ์ด๋Š” ๊ฒฐ๊ตญ ์ •์ฑ… ์ผ๊ด€์„ฑ ๋ถ•๊ดด(Policy Enforcement Inconsistency), ๋ณด์•ˆ ์˜ˆ์ธก ์‹คํŒจ(Security Predictability Failure), ์‹ ๋ขฐ ์‚ฌ์Šฌ ๋ฌด๋ ฅํ™”(Trust Chain Breakdown)๋กœ ์ด์–ด์งˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.


์œ„ํ˜‘ ํ๋ฆ„ ์˜ˆ์‹œ:

  1. ํ•˜๋‚˜์˜ ๋ฌธ๋งฅ(Context Payload)์ด ์—ฌ๋Ÿฌ ์‹œ์Šคํ…œ์— ๋ถ„์‚ฐ ์ „๋‹ฌ๋ฉ๋‹ˆ๋‹ค.
  2. ๊ฐ ์‹œ์Šคํ…œ์€ ๋กœ์ปฌ์— ๋‚ด์žฅ๋œ LLM ๋˜๋Š” ์ •์ฑ… ํ•ด์„ ์—”์ง„์„ ํ†ตํ•ด ๋ฌธ๋งฅ์„ ํ‰๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.
  3. ์ •์ฑ… ๋กœ์ง ๋˜๋Š” ์‹คํ–‰ ์ •์ฑ… ๋ฒ„์ „์ด ์„œ๋กœ ๋‹ฌ๋ผ, ์ผ๋ถ€ ์‹œ์Šคํ…œ์—์„œ๋Š” ์š”์ฒญ์„ ํ—ˆ์šฉํ•˜๊ณ  ์ผ๋ถ€์—์„œ๋Š” ์ฐจ๋‹จ๋ฉ๋‹ˆ๋‹ค.
  4. ์ด๋กœ ์ธํ•ด ๋™์ผํ•œ ์š”์ฒญ์— ๋Œ€ํ•ด ๋ณด์•ˆ ์ •์ฑ… ๊ฒฐ๊ณผ๊ฐ€ ์ผ๊ด€๋˜์ง€ ์•Š๊ฒŒ ์ฒ˜๋ฆฌ๋˜๋ฉฐ, ์ „์‚ฌ ์‹œ์Šคํ…œ์˜ ์ •์ฑ… ํ†ต์ œ๋ ฅ์ด ์•ฝํ™”๋ฉ๋‹ˆ๋‹ค.

์ฝ”๋“œ ์˜ˆ์‹œ: ๋™์ผ ๋ฌธ๋งฅ์˜ ๋…ธ๋“œ๋ณ„ ์ •์ฑ… ํ•ด์„ ์ฐจ์ด

// ์ „๋‹ฌ๋œ ๋ฌธ๋งฅ (Context Payload)
{
  "user": {
    "id": "dev_user",
    "role": "editor"
  },
  "request": {
    "action": "publish"
  },
    "context": {
    "project": "prod-marketing",
    "env": "staging"
  }
}
# Node A (์ •์ฑ… ํ•ด์„: editor๋Š” publish ๊ฐ€๋Šฅ)
package access

default allow = false

allow {
  input.user.role == "editor"
  input.request.action == "publish"
}
# Node B (์ •์ฑ… ํ•ด์„: publish๋Š” admin๋งŒ ๊ฐ€๋Šฅ)
package access

default allow = false

allow {
  input.user.role == "admin"
  input.request.action == "publish"
}

๋™์ผํ•œ Context๋ฅผ ์ „๋‹ฌ๋ฐ›์€ ๋‘ ๋…ธ๋“œ๋Š” ์ƒ๋ฐ˜๋œ ์ •์ฑ… ํŒ๋‹จ์„ ๋‚ด๋ฆฌ๋ฉฐ, ํ•œ ์‹œ์Šคํ…œ์€ ์š”์ฒญ์„ ์Šน์ธํ•˜๊ณ  ๋‹ค๋ฅธ ์‹œ์Šคํ…œ์€ ์ฐจ๋‹จํ•˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค. ์ด๋กœ ์ธํ•ด ์ •์ฑ… ์ผ๊ด€์„ฑ(Policy Consistency)์ด ๋ถ•๊ดด๋˜๊ณ , ๋ณด์•ˆ ์˜ˆ์ธก ๊ฐ€๋Šฅ์„ฑ(Security Predictability)์ด ์‚ฌ๋ผ์ง€๋ฉฐ, ์‹ ๋ขฐ ๊ฒฝ๊ณ„๋ฅผ ์œ ์ง€ํ•˜๊ธฐ ์–ด๋ ค์›Œ์ง‘๋‹ˆ๋‹ค.


๋ณด์•ˆ ์‹คํŒจ ํฌ์ธํŠธ

  • ์ •์ฑ… ํ•ด์„์˜ ์ง€์—ญ์„ฑ(Localized Policy Evaluation)

์ •์ฑ… ๋กœ์ง์ด ์‹คํ–‰ ๋…ธ๋“œ๋ณ„๋กœ ๋ถ„์‚ฐ๋˜์–ด ์žˆ์œผ๋ฉฐ, ์ค‘์•™ ํ†ต์ œ๊ฐ€ ์ด๋ฃจ์–ด์ง€์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

  • ํ‘œ์ค€ํ™”๋œ ์ •์ฑ… ์ •์˜์˜ ๋ถ€์žฌ(Lack of Standardized Policy Templates)

์กฐ์ง ์ „์ฒด์—์„œ ์‚ฌ์šฉํ•˜๋Š” Rego ์ •์ฑ…์ด ํ†ต์ผ๋˜์–ด ์žˆ์ง€ ์•Š์•„ ๋…ธ๋“œ ๊ฐ„ ์ •์ฑ… ํŽธ์ฐจ๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.

  • Context์— ์‹คํ–‰ ํ™˜๊ฒฝ ์ •๋ณด ๋ฏธํฌํ•จ(No Execution Metadata)

Context Payload ์ž์ฒด์— ์‹คํ–‰ ๋Œ€์ƒ ํ™˜๊ฒฝ(OS, Region, Runtime ๋ฒ„์ „ ๋“ฑ)์„ ๋ช…์‹œํ•˜์ง€ ์•Š์•„ ์ผ๊ด€๋œ ํ•ด์„ ๊ฒฝ๋กœ๋ฅผ ์ œ๊ณตํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

  • ์ •์ฑ… ์—”์ง„์˜ ๋น„๋™๊ธฐํ™”(Policy Engine Desynchronization)

MCP Agent ๋˜๋Š” LLM Runtime ๊ฐ„์˜ ์ •์ฑ… ํ•ด์„ ๊ธฐ์ค€์ด ๋™๊ธฐํ™”๋˜์ง€ ์•Š์•„, ์‹ ๋ขฐ ์ฒด์ธ(Trust Chain)์ด ์•ฝํ™”๋ฉ๋‹ˆ๋‹ค.


์‹œ๋‚˜๋ฆฌ์˜ค D: ๋ฌธ๋งฅ ํ๋ฆ„์˜ ๋กœ๊น… ๋ˆ„๋ฝ์œผ๋กœ ์ธํ•œ ์‚ฌ๊ณ  ์ถ”์  ์‹คํŒจ (T4)

MCP ์‹œ์Šคํ…œ์—์„œ๋Š” ์—์ด์ „ํŠธ ๊ฐ„ ๋ฌธ๋งฅ(Context) ์ •๋ณด๊ฐ€ ์ง€์†์ ์œผ๋กœ ์ „๋‹ฌ๋˜๊ณ  ํ‰๊ฐ€๋˜๋ฉฐ, ์ด ๊ณผ์ •์€ ์ •์ฑ… ์ง‘ํ–‰ ํ๋ฆ„์˜ ํ•ต์‹ฌ ๊ทผ๊ฑฐ๊ฐ€ ๋ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ๋ฌธ๋งฅ ํ๋ฆ„์— ๋Œ€ํ•œ ๋กœ๊น…์ด ๋ˆ„๋ฝ๋˜๊ฑฐ๋‚˜, ๋น„ํ‘œ์ค€ ํฌ๋งท์œผ๋กœ ๊ธฐ๋ก๋˜๊ฑฐ๋‚˜, ์•”ํ˜ธํ™”๋˜์–ด ํ•ด์„์ด ์–ด๋ ค์šด ๊ฒฝ์šฐ, ์‚ฌ๊ณ  ๋ฐœ์ƒ ์‹œ ์‹œ์Šคํ…œ์˜ ๊ฐ์‚ฌ ์ถ”์ (Audit Traceability)์ด ์‚ฌ์‹ค์ƒ ๋ถˆ๊ฐ€๋Šฅํ•ด์ง‘๋‹ˆ๋‹ค. ์ด๋Š” ๊ฐ์‚ฌ ๋ถˆ๊ฐ€๋Šฅ์„ฑ(Audit Invisibility)์œผ๋กœ ์ด์–ด์ง€๋ฉฐ, ๊ฒฐ๊ณผ์ ์œผ๋กœ ๊ทœ์ œ ๋ถˆ์ดํ–‰(Compliance Failure), ํฌ๋ Œ์‹ ๋ถ„์„ ์ฐจ๋‹จ(Forensic Analysis Obstruction), ๋ณด์•ˆ ๋Œ€์‘ ์ง€์—ฐ(Security Response Delay) ๋“ฑ์˜ ๋ณด์•ˆ ์‹คํŒจ๋ฅผ ์œ ๋ฐœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.


์œ„ํ˜‘ ํ๋ฆ„ ์˜ˆ์‹œ:

  1. ์‚ฌ์šฉ์ž๋Š” ์‹œ์Šคํ…œ ๋‚ด ํŠน์ • ์ž‘์—…์„ ์š”์ฒญํ•ฉ๋‹ˆ๋‹ค.
  2. ํ•ด๋‹น ์š”์ฒญ์€ MCP Context๋กœ ํฌ์žฅ๋˜์–ด ์—ฌ๋Ÿฌ ์—์ด์ „ํŠธ์™€ MCP ์„œ๋ฒ„๋ฅผ ๊ฑฐ์ณ ์ „๋‹ฌ๋ฉ๋‹ˆ๋‹ค.
  3. ๋„์ค‘์— ๋น„์ธ๊ฐ€๋œ ๋ฌธ๋งฅ ๋ณ€๊ฒฝ ๋˜๋Š” ์•…์„ฑ ์œ„์ž„ ์š”์ฒญ์ด ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.
  4. MCP ์„œ๋ฒ„๋Š” ์ด๋ฒคํŠธ๋ฅผ ๊ธฐ๋กํ•˜์ง€๋งŒ, Context ID, ์ˆ˜ํ–‰ ์—์ด์ „ํŠธ, ์‹คํ–‰ ๊ฒฐ๊ณผ ๋“ฑ ํ•ต์‹ฌ ์ •๋ณด๊ฐ€ ๋ˆ„๋ฝ๋˜๊ฑฐ๋‚˜, ํ•ด์„ํ•  ์ˆ˜ ์—†๋Š” ์•”ํ˜ธํ™” ํ˜•ํƒœ๋กœ ์ €์žฅ๋ฉ๋‹ˆ๋‹ค.
  5. ๋ณด์•ˆ ์šด์˜์ž๋Š” ๊ณต๊ฒฉ์˜ ์‹คํ–‰ ๊ฒฝ๋กœ์™€ ์ฑ…์ž„ ์ฃผ์ฒด๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

์ฝ”๋“œ ์˜ˆ์‹œ: ๋ถˆ์™„์ „ํ•œ ๋กœ๊ทธ ๊ธฐ๋ก

// ๋น„ํ‘œ์ค€ ๋กœ๊ทธ ์ƒ˜ํ”Œ (๋‚ด์šฉ ์ถ•์•ฝ, ํ•„๋“œ ๋ˆ„๋ฝ)
{
    "event": "context_execution",
    "context_id": "ctx_1132abc",
    "timestamp": "2025-04-10T02:15:23Z",
    "status": "executed"
}
// ๊ธฐ๋Œ€๋˜๋Š” ๋กœ๊ทธ ํฌ๋งท ์˜ˆ์‹œ (๊ตฌ์กฐํ™”๋˜๊ณ  ๊ฒ€์ฆ ๊ฐ€๋Šฅํ•œ ํ˜•ํƒœ)
{
    "event": "context_execution",
    "context_id": "ctx_1132abc",
    "agent": {
        "id": "agent_X7",
        "signature_valid": true
    },
    "policy": {
        "evaluated": true,
        "result": "allow"
    },
    "request": {
        "action": "delete_account",
        "initiated_by": "user_0841"
    },
    "timestamp": "2025-04-10T02:15:23Z",
    "hash": "b324f8a6c1..."
}

์ฒซ ๋ฒˆ์งธ ๋กœ๊ทธ๋Š” ๊ธฐ์ˆ ์  ์ด๋ฒคํŠธ๋งŒ ๊ธฐ๋ก๋˜์–ด ์žˆ์œผ๋ฉฐ, ๋ณด์•ˆ ํŒ๋‹จ ๋˜๋Š” ์ •์ฑ… ํ๋ฆ„์„ ํ™•์ธํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. ๋‘ ๋ฒˆ์งธ ๋กœ๊ทธ๋Š” ์ •์ฑ… ๊ฒฐ๊ณผ, ์‹คํ–‰ ์ฃผ์ฒด, ์„œ๋ช… ๊ฒ€์ฆ ์ƒํƒœ ๋“ฑ์„ ํฌํ•จํ•˜์—ฌ ๊ฐ์‚ฌ์™€ ํฌ๋ Œ์‹ ๋ถ„์„์ด ๊ฐ€๋Šฅํ•œ ์ˆ˜์ค€์˜ ๊ตฌ์กฐํ™”๋œ ๊ธฐ๋ก์ž…๋‹ˆ๋‹ค.


๋ณด์•ˆ ์‹คํŒจ ํฌ์ธํŠธ

  • Context ํ๋ฆ„์˜ ๊ตฌ์กฐํ™”๋œ ๋กœ๊ทธ ๋ฏธ์ƒ์„ฑ(Unstructured Context Flow Logging) ๋‹จ์ผ ์ด๋ฒคํŠธ ์ˆ˜์ค€์˜ ๋กœ๊ทธ๋งŒ ์กด์žฌํ•˜๋ฉฐ, ์ •์ฑ… ์ ์šฉ ์ด๋ ฅ ๋˜๋Š” ์‹คํ–‰ ๊ฒฝ๋กœ ์ถ”์ ์ด ๋ถˆ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

  • ํ‘œ์ค€ ํฌ๋งท ๋ฏธ์‚ฌ์šฉ(Non-standard Log Format) ๋กœ๊ทธ ํ•„๋“œ๊ฐ€ ์ผ๊ด€๋˜์ง€ ์•Š๊ฑฐ๋‚˜ ํ•„์ˆ˜ ํ•ญ๋ชฉ(agent, policy, result ๋“ฑ)์ด ๋ˆ„๋ฝ๋˜์–ด ํ•ด์„์ด ์–ด๋ ต์Šต๋‹ˆ๋‹ค.

  • ๋กœ๊ทธ ๋ณ€์กฐ ํƒ์ง€ ๋ฏธ๊ตฌํ˜„(No Log Integrity Validation) ๋กœ๊ทธ์— ๋Œ€ํ•œ ์„œ๋ช… ๋˜๋Š” ํ•ด์‹œ๊ฐ’ ๊ฒ€์ฆ์ด ์—†์–ด ๋ณ€์กฐ ์—ฌ๋ถ€๋ฅผ ์‹๋ณ„ํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

  • ์‹œ์Šคํ…œ ๊ฐ„ ๋กœ๊ทธ ์—ฐ๊ณ„ ๋ถ€์žฌ(No End-to-End Log Correlation) ์—์ด์ „ํŠธ ๊ฐ„ ๋˜๋Š” MCP Server ๊ฐ„ ์—ฐ๊ณ„ ๋กœ๊ทธ ID๊ฐ€ ์—†์œผ๋ฏ€๋กœ, ํ•˜๋‚˜์˜ ์š”์ฒญ์— ๋Œ€ํ•œ ์ „์ฒด ๊ฒฝ๋กœ ์ถ”์ ์ด ์–ด๋ ต์Šต๋‹ˆ๋‹ค.


์‹œ๋‚˜๋ฆฌ์˜ค E: ์ •์ฑ… ํ•ด์„์ž์™€ ์‹คํ–‰ ์—”์ง„ ๊ฐ„์˜ ๋ถ„๋ฆฌ๋กœ ์ธํ•œ ์ •์ฑ…-ํ–‰์œ„ ๋ถˆ์ผ์น˜ (T2, T3)

MCP ๊ธฐ๋ฐ˜ ์‹œ์Šคํ…œ์—์„œ๋Š” ์ •์ฑ… ํ•ด์„(Policy Evaluation)์„ ๋‹ด๋‹นํ•˜๋Š” ๋ชจ๋“ˆ๊ณผ ์‹ค์ œ ํ–‰์œ„๋ฅผ ์ˆ˜ํ–‰ํ•˜๋Š” ์‹คํ–‰ ์—”์ง„(Runtime Executor), ์˜ˆ: LLM ๋˜๋Š” ์˜ค์ผ€์ŠคํŠธ๋ ˆ์ดํ„ฐ๊ฐ€ ๋ถ„๋ฆฌ๋œ ์•„ํ‚คํ…์ฒ˜๋กœ ๊ตฌ์„ฑ๋˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋งŽ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ๊ตฌ์กฐ์—์„œ๋Š” ์ •์ฑ…์˜ ํŒ๋‹จ ๊ฒฐ๊ณผ์™€ ์‹ค์ œ ์‹คํ–‰ ๊ฐ„์˜ ๋ถˆ์ผ์น˜(Inconsistency between Policy Decision and Runtime Behavior)๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์ด๋Š” ์ •์ฑ… ์šฐํšŒ(Policy Bypass) ๋˜๋Š” ๊ถŒํ•œ ์˜ค์šฉ(Privilege Misuse)์œผ๋กœ ์ด์–ด์งˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ •์ฑ…๊ณผ ์‹คํ–‰ ์ฃผ์ฒด๊ฐ€ ๋ฌผ๋ฆฌ์  ๋˜๋Š” ๋…ผ๋ฆฌ์ ์œผ๋กœ ๋ถ„๋ฆฌ๋˜์–ด ์žˆ์„ ๊ฒฝ์šฐ, ์‹ค์ œ ํ–‰๋™์ด ์ •์ฑ… ๋…ผ๋ฆฌ๋ฅผ ๋”ฐ๋ฅด์ง€ ์•Š๊ณ  ๋™์ž‘ํ•  ์ˆ˜ ์žˆ๋‹ค๋Š” ์ ์ด ํ•ต์‹ฌ ์œ„ํ˜‘ ์š”์†Œ์ž…๋‹ˆ๋‹ค.


์œ„ํ˜‘ ํ๋ฆ„ ์˜ˆ์‹œ

  1. ์‚ฌ์šฉ์ž๊ฐ€ MCP ๊ธฐ๋ฐ˜ LLM ์‹œ์Šคํ…œ์— ์ž‘์—… ์š”์ฒญ์„ ๋ณด๋ƒ…๋‹ˆ๋‹ค.
  2. ์ •์ฑ… ์—”์ง„(Open Policy Agent ๋“ฑ)์€ ์ด ์š”์ฒญ์— ๋Œ€ํ•ด โ€œ๊ฑฐ๋ถ€(deny)โ€ ๊ฒฐ์ •์„ ๋‚ด๋ฆฝ๋‹ˆ๋‹ค.
  3. ๊ทธ๋Ÿฌ๋‚˜ ์ •์ฑ… ํ•ด์„ ๊ฒฐ๊ณผ๊ฐ€ ์‹คํ–‰ ์—”์ง„์— ์ „๋‹ฌ๋˜์ง€ ์•Š๊ฑฐ๋‚˜, ์ „๋‹ฌ๋˜์—ˆ์Œ์—๋„ ์‹คํ–‰ ์—”์ง„์€ ๋กœ์ปฌ ๋ฌธ๋งฅ๋งŒ ๊ธฐ์ค€์œผ๋กœ ํ–‰๋™์„ ๊ฒฐ์ •ํ•ฉ๋‹ˆ๋‹ค.
  4. ๊ฒฐ๊ณผ์ ์œผ๋กœ ์ •์ฑ…์—์„œ ํ—ˆ์šฉํ•˜์ง€ ์•Š์€ ์š”์ฒญ์ด ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค.
  5. ์ด๋Š” ๋ณด์•ˆ ์ •์ฑ… ๋ฌด๋ ฅํ™”(Security Policy Circumvention)๋กœ ์ด์–ด์ง€๋ฉฐ, ์‹œ์Šคํ…œ์ด ์‹ ๋ขฐ ๋ถˆ๊ฐ€๋Šฅํ•œ ์ƒํƒœ๋กœ ์ „ํ™˜๋ฉ๋‹ˆ๋‹ค.

์ฝ”๋“œ ์˜ˆ์‹œ: ์ •์ฑ… ํ•ด์„๊ณผ ์‹คํ–‰์˜ ๋ถˆ์ผ์น˜

# ์ •์ฑ… ์—”์ง„ (์˜ˆ: OPA์—์„œ ์‹คํ–‰)
package policy.access

default allow = false

allow {
  input.user.role == "manager"
  input.request.action == "delete_user"
}
// Context Payload (LLM์ด ๋ฐ›์•„๋“ค์ด๋Š” ์ž…๋ ฅ)
{
  "user": {
    "id": "user_042",
    "role": "analyst"
  },
    "action": "delete_user"
    "request": {
  }
}
# ์‹คํ–‰ ์—”์ง„ ๋‚ด๋ถ€ ๋กœ์ง (LLM/Agent ๋‚ด๋ถ€)
if context["user"]["authenticated"] and context["request"]["action"] == "delete_user":
    perform_deletion()

์ •์ฑ… ์—”์ง„์€ role != manager์ด๋ฏ€๋กœ ์‚ญ์ œ ์š”์ฒญ์„ ๊ฑฐ๋ถ€ํ•ด์•ผ ํ•˜์ง€๋งŒ, ์‹คํ–‰ ์—”์ง„์€ ๋‹จ์ˆœํžˆ authenticated ์ƒํƒœ๋งŒ ํ™•์ธํ•˜๊ณ  ์‚ญ์ œ๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค. ์ด๋กœ ์ธํ•ด ์ •์ฑ…-ํ–‰์œ„ ๊ฐ„ ๋ถˆ์ผ์น˜(Policy-Behavior Mismatch)๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.


๋ณด์•ˆ ์‹คํŒจ ํฌ์ธํŠธ

  • ์ •์ฑ… ํŒ๋‹จ ๊ฒฐ๊ณผ์™€ ์‹คํ–‰ ๋กœ์ง ๊ฐ„ ์ „๋‹ฌ ๋ฏธ๋น„(Missing Policy Binding)

์ •์ฑ… ์—”์ง„์˜ ํŒ๋‹จ์ด ์‹คํ–‰ ์—”์ง„์— ์‹ค์‹œ๊ฐ„์œผ๋กœ ๋ฐ˜์˜๋˜์ง€ ์•Š๊ฑฐ๋‚˜, ์ƒํƒœ๊ฐ€ ๊ณต์œ ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

  • ์‹คํ–‰ ์—”์ง„์˜ ๋ฌธ๋งฅ ๊ธฐ๋ฐ˜ ๋กœ์ง ๋‹จ๋… ์‹คํ–‰(Context-only Logic Execution)

์‹คํ–‰ ์—”์ง„์ด ๋ณ„๋„์˜ ์ •์ฑ… ํŒ๋‹จ ์—†์ด, ๋กœ์ปฌ ๋ฌธ๋งฅ๋งŒ์œผ๋กœ ํŒ๋‹จ์„ ๋‚ด๋ฆฌ๊ณ  ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

  • ์ •์ฑ… ํ†ตํ•ฉ ๊ฒ€์ฆ ๋ฏธํก(No Policy-Enforced Runtime Contracts)

์ •์ฑ…๊ณผ ์‹คํ–‰ ์—”์ง„ ๊ฐ„์— โ€œ์‹คํ–‰ ์กฐ๊ฑด = ์ •์ฑ… ์Šน์ธโ€์ด๋ผ๋Š” ๋ถˆ๋ณ€ ์กฐ๊ฑด์ด ์ ์šฉ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

  • ์ค‘๊ฐ„ ๊ณ„์ธต์˜ ์ •์ฑ… ๋ฌด๋ ฅํ™” ๊ฐ€๋Šฅ์„ฑ(Intermediary Override Risk)

์ค‘๊ฐ„ ์˜ค์ผ€์ŠคํŠธ๋ ˆ์ดํ„ฐ ๋˜๋Š” ๋ผ์šฐํ„ฐ๊ฐ€ ์ •์ฑ… ๊ฒฐ๊ณผ๋ฅผ ๋ฌด์‹œํ•˜๊ฑฐ๋‚˜ ๋ฎ์–ด์“ธ ์ˆ˜ ์žˆ๋Š” ๊ตฌ์กฐ์  ์œ„ํ—˜์ด ์กด์žฌํ•ฉ๋‹ˆ๋‹ค.


๊ตฌ์กฐ์  ๋ณด์•ˆ ์ทจ์•ฝ์  ์š”์•ฝ

MCP ๊ธฐ๋ฐ˜ ์‹œ์Šคํ…œ์—์„œ ๋ฐœ๊ฒฌ๋œ ๋ณด์•ˆ ์œ„ํ˜‘์€ ๋‹จ์ผ ์ทจ์•ฝ์ ์ด ์•„๋‹Œ, MCP ์•„ํ‚คํ…์ฒ˜ ์ „๋ฐ˜์— ๊ฑธ์ณ ์กด์žฌํ•˜๋Š” ๊ตฌ์กฐ์  ๋ณด์•ˆ ๊ฒฐํ•จ(Structural Security Weaknesses)์—์„œ ๊ธฐ์ธํ•ฉ๋‹ˆ๋‹ค. ์ฃผ์š” ์ทจ์•ฝ์ ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค:

์ทจ์•ฝ ํ•ญ๋ชฉ์„ค๋ช…
๋น„ํ‘œ์ค€ ๋ฌธ๋งฅ ํ˜•์‹ (Non-standard Context Schema)์‹œ์Šคํ…œ ๊ฐ„ ๋ฌธ๋งฅ(Context) ๊ตฌ์กฐ๊ฐ€ ํ†ต์ผ๋˜์ง€ ์•Š์•„ ๋™์ผ ๋ฌธ๋งฅ์ด ๋‹ค๋ฅด๊ฒŒ ํ•ด์„๋  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์ •์ฑ… ์ผ๊ด€์„ฑ ํ™•๋ณด๊ฐ€ ์–ด๋ ต์Šต๋‹ˆ๋‹ค.
์‹คํ–‰ ํ™˜๊ฒฝ ๋น„๊ฒฐ์ •์„ฑ (Execution Non-determinism)LLM ๋˜๋Š” Agent์˜ ๋กœ์ปฌ ์„ค์ •, ์ •์ฑ… ๋ฒ„์ „, ํ•ด์„๊ธฐ ์ข…๋ฅ˜ ๋“ฑ์— ๋”ฐ๋ผ ๋™์ผ ์š”์ฒญ์ด ๋‹ค๋ฅธ ๊ฒฐ๊ณผ๋ฅผ ์œ ๋ฐœํ•ฉ๋‹ˆ๋‹ค.
์ •์ฑ… ํ•ด์„์ž์™€ ์‹คํ–‰ ์—”์ง„์˜ ๋ถ„๋ฆฌ (Policy-Executor Separation)์ •์ฑ… ํŒ๋‹จ๊ณผ ์‹ค์ œ ํ–‰๋™ ์ฃผ์ฒด๊ฐ€ ๋ถ„๋ฆฌ๋˜์–ด ์žˆ์–ด ์ •์ฑ… ์œ„๋ฐ˜์ด ์‹คํ–‰ ๋กœ์ง์—์„œ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
๋กœ๊น… ํ‘œ์ค€ ๋ถ€์žฌ ๋ฐ ๊ฐ์‚ฌ ๋ถˆ๊ฐ€์„ฑ (Lack of Logging Standardization and Audit Invisibility)Context ํ๋ฆ„์— ๋Œ€ํ•œ ๋กœ๊ทธ๊ฐ€ ๋ˆ„๋ฝ๋˜๊ฑฐ๋‚˜ ๋น„ํ‘œ์ค€ ํฌ๋งท์œผ๋กœ ์ €์žฅ๋˜์–ด ์‚ฌ๊ณ  ๋ฐœ์ƒ ์‹œ ์ถ”์ ์ด ๋ถˆ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

์ด๋Ÿฌํ•œ ๊ตฌ์กฐ์  ์ทจ์•ฝ์ ๋“ค์€ MCP๊ฐ€ ์„ค๊ณ„ ์˜๋„์™€๋Š” ๋‹ฌ๋ฆฌ, ์ƒํƒœ ๋ถˆ์ผ์น˜, ์ •์ฑ… ์šฐํšŒ, ๋น„์ธ๊ฐ€ ์‹คํ–‰, ๋ณด์•ˆ ์˜ˆ์ธก ์‹คํŒจ์™€ ๊ฐ™์€ ๋ณตํ•ฉ์  ๋ณด์•ˆ ๋ฆฌ์Šคํฌ๋ฅผ ๋‚ดํฌํ•˜๊ณ  ์žˆ์Œ์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.

์œ„ํ˜‘ ์œ ํ˜•๊ณผ ์‹œ์Šคํ…œ ๊ณ„์ธต ๊ฐ„ ์—ฐ๊ด€ ๊ด€๊ณ„

๋ณด์•ˆ ์œ„ํ˜‘์˜ ์ •ํ™•ํ•œ ๋Œ€์‘์„ ์œ„ํ•ด, MCP ์‹œ์Šคํ…œ ๊ตฌ์„ฑ ์š”์†Œ์™€ ๊ฐ ์œ„ํ˜‘ ์œ ํ˜• ๊ฐ„์˜ ์˜ํ–ฅ์„ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ •๋ฆฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

์œ„ํ˜‘ ์œ ํ˜•์ฃผ์š” ํ•˜์œ„ ์š”์†Œ์˜ํ–ฅ์„ ๋ฐ›๋Š” ์‹œ์Šคํ…œ ๊ณ„์ธต
T1 ๋ฌธ๋งฅ ์กฐ์ž‘ (Context Injection)์œ„์กฐ๋œ ๋ฌธ๋งฅ, ์‹คํ–‰ ์กฐ๊ฑด ๋ณ€์กฐLLM Runtime / Input Processor
T2 ์œ„์ž„ ์ฒด๊ณ„ ๋‚จ์šฉ (Delegation Abuse)์œ„์ž„ ์‚ฌ์นญ, ๊ถŒํ•œ ๋ฒ”์œ„ ์ดˆ๊ณผPolicy Engine / Agent Hub
T3 ์‹คํ–‰ ๊ฒฐ๊ณผ ๋น„๊ฒฐ์ •์„ฑ (Execution Divergence)์ •์ฑ… ํŒ๋‹จ ๋ถˆ์ผ์น˜, ํ™˜๊ฒฝ ํŽธ์ฐจLLM Runtime / Policy Evaluator
T4 ๊ฐ์‚ฌ ๋ถˆ๊ฐ€์„ฑ (Audit Invisibility)๋กœ๊ทธ ๋ˆ„๋ฝ, ๋น„ํ‘œ์ค€ ํฌ๋งท, ์ถ”์  ๋ถˆ๊ฐ€MCP Server / SIEM / Audit Layer

์ด ๋งคํ•‘์€ Section 4์—์„œ ์ œ์‹œ๋  ๋Œ€์‘ ์ „๋žต์ด ์–ด๋–ค ๊ณ„์ธต์˜ ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜์— ์ ์šฉ๋˜์–ด์•ผ ํ•˜๋Š”์ง€๋ฅผ ํŒ๋‹จํ•˜๋Š” ๊ธฐ์ค€์ด ๋ฉ๋‹ˆ๋‹ค.

์œ„ํ˜‘ ๊ตฌ์กฐ ์š”์•ฝ ๋ฐ ์ „๋žต ๋Œ€์‘ ๋ฐฉํ–ฅ

์ง€๊ธˆ๊นŒ์ง€ ๋ถ„์„ํ•œ ๋ฐ”์™€ ๊ฐ™์ด MCP ๊ธฐ๋ฐ˜ ์‹œ์Šคํ…œ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ „๋ฐฉ์œ„์  ๋ณด์•ˆ ์œ„ํ˜‘์„ ๋‚ดํฌํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค:

  • ๋ฌธ๋งฅ ์ „๋‹ฌ์˜ ๋ฌด๊ฒฐ์„ฑ ๋ฐ ์‹ ๋ขฐ์„ฑ ๊ฒฐ์—ฌ (Integrity & Trust Deficiency in Context Flow)
  • ๋ณด์•ˆ ์ •์ฑ…์˜ ์ผ๊ด€๋œ ํ•ด์„ ์‹คํŒจ (Inconsistent Policy Interpretation)
  • ์‹คํ–‰ ๊ณ„์ธต์˜ ์ •์ฑ… ๋น„์ˆœ์‘ ๋™์ž‘ (Non-compliant Runtime Behavior)
  • ๋ฌธ๋งฅ ํ๋ฆ„์— ๋Œ€ํ•œ ์‚ฌํ›„ ๊ฐ์‚ฌ ๋ถˆ๊ฐ€๋Šฅ (Audit Invisibility)

์ด๋Ÿฌํ•œ ์œ„ํ˜‘์€ ์‹œ์Šคํ…œ์˜ ๋ณด์•ˆ ํ†ต์ œ๋ ฅ, ์ •์ฑ… ์ง‘ํ–‰ ์‹ ๋ขฐ์„ฑ, ๊ทœ์ œ ๋Œ€์‘ ๋Šฅ๋ ฅ ๋“ฑ ํ•ต์‹ฌ ๋ณด์•ˆ ์†์„ฑ(Core Security Attributes)์„ ์ง์ ‘์ ์œผ๋กœ ์•ฝํ™”์‹œํ‚ค๋ฉฐ, MCP๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•œ AI ์ธํ”„๋ผ ์ „๋ฐ˜์˜ ๋ณด์•ˆ ์‹ ๋ขฐ๋„(Security Assurance)๋ฅผ ์œ„ํ˜‘ํ•˜๋Š” ์š”์†Œ๋กœ ์ž‘์šฉํ•ฉ๋‹ˆ๋‹ค. ๋”ฐ๋ผ์„œ Section 4์—์„œ๋Š” ์œ„์—์„œ ๋„์ถœํ•œ T1~T4 ์œ„ํ˜‘ ์œ ํ˜•๋ณ„ ๋ถ„์„์„ ๋ฐ”ํƒ•์œผ๋กœ, ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ „๋žต ๋ฐฉํ–ฅ์„ ์ค‘์‹ฌ์œผ๋กœ ๊ธฐ์ˆ ์ ยท์ •์ฑ…์  ๋Œ€์‘ ๋ฐฉ์•ˆ(Security Countermeasures)์„ ์ œ์•ˆํ•ฉ๋‹ˆ๋‹ค:

  • ์ •์ฑ… ํ•ด์„๊ณผ ์‹คํ–‰ ๊ฐ„์˜ ๋ถˆ์ผ์น˜ ์ œ๊ฑฐ
  • ๋ฌธ๋งฅ ํ๋ฆ„์˜ ๋ฌด๊ฒฐ์„ฑ ๋ณด์žฅ
  • ๊ถŒํ•œ ์œ„์ž„์˜ ์ œํ•œ๊ณผ ์ถ”์  ๊ฐ€๋Šฅ์„ฑ ํ™•๋ณด
  • ๊ฐ์‚ฌ ๊ธฐ๋Šฅ์˜ ๊ตฌ์กฐํ™” ๋ฐ ํ‘œ์ค€ํ™”

์ด๋ฅผ ํ†ตํ•ด MCP ๊ธฐ๋ฐ˜ ์‹œ์Šคํ…œ์˜ ๋ณด์•ˆ์„ฑ๊ณผ ์šด์˜ ์•ˆ์ •์„ฑ์„ ๋™์‹œ์— ํ™•๋ณดํ•  ์ˆ˜ ์žˆ๋Š” ์‹ค์งˆ์  ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜ ๊ฐœ์„  ๋ฐฉํ–ฅ์„ ๋„์ถœํ•ฉ๋‹ˆ๋‹ค.

4. ๋ถ„์„ ๊ธฐ๋ฐ˜ ์ „๋žต ์ œ์–ธ

๋Œ€์‘ ์ „๋žต ๊ฐœ์š”

์•ž์„œ Section 3์—์„œ ์ œ์‹œ๋œ MCP ๊ธฐ๋ฐ˜ ๋ณด์•ˆ ์œ„ํ˜‘์€ ๋‹ค์Œ์˜ ์„ธ ๊ฐ€์ง€ ๋ณด์•ˆ ์›์น™์„ ์ค‘์‹ฌ์œผ๋กœ ๋Œ€์‘ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

  • ์ •์ฑ… ์ผ๊ด€์„ฑ (Policy Consistency): ๊ถŒํ•œ ์œ„์ž„, ์‹คํ–‰ ์กฐ๊ฑด, ๊ฐ์‚ฌ ๊ธฐ์ค€ ๋“ฑ ๋ณด์•ˆ ์ •์ฑ…์ด ์—์ด์ „ํŠธยทLLMยท์„œ๋ฒ„ ๊ณ„์ธต์— ์ผ๊ด€๋˜๊ฒŒ ์ ์šฉ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
  • ์‹ค์‹œ๊ฐ„ ํƒ์ง€ (Real-time Detection): ๋ฌธ๋งฅ ๋ณ€์กฐ, ์ •์ฑ… ์šฐํšŒ, LLM ์˜ค์ž‘๋™์„ ์ฆ‰์‹œ ํƒ์ง€ํ•  ์ˆ˜ ์žˆ๋Š” ํ†ตํ•ฉ ํƒ์ง€ ์ฒด๊ณ„๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.
  • ๊ฐ์‚ฌ ๊ฐ€๋Šฅ์„ฑ (Auditability): MCP์˜ ์‹คํ–‰ ํ๋ฆ„๊ณผ ๋ฌธ๋งฅ ์ „๋‹ฌ ๋‚ด์—ญ์ด ๋ชจ๋“  ๊ณ„์ธต์—์„œ ์ถ”์ ์ด ๊ฐ€๋Šฅํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์ „๋žต A: ์ •์ฑ… ์ผ๊ด€์„ฑ ํ™•๋ณด ๋ฐ ์‹คํ–‰ ์—ฐ๋™

์ „๋žต ๋ชฉํ‘œ

์ •์ฑ… ํŒ๋‹จ(Policy Evaluation)๊ณผ ์‹คํ–‰ ๋กœ์ง(Runtime Execution) ๊ฐ„์˜ ๋…ผ๋ฆฌ์  ์ผ๊ด€์„ฑ(Logical Consistency)์„ ํ™•๋ณดํ•˜์—ฌ, ์ •์ฑ… ์œ„๋ฐ˜ ํ–‰์œ„๊ฐ€ ์‹ค์ œ ์‹คํ–‰์—์„œ ์ฐจ๋‹จ๋  ์ˆ˜ ์žˆ๋„๋ก ํ•ฉ๋‹ˆ๋‹ค. ์ด๋Š” ํŠนํžˆ ์‹คํ–‰ ํ™˜๊ฒฝ์ด LLM ๋˜๋Š” ๋‹ค์ค‘ Agent ๊ธฐ๋ฐ˜์ผ ๊ฒฝ์šฐ, ์ •์ฑ…๊ณผ ํ–‰๋™ ๊ฐ„ ๋ถ„๋ฆฌ๋ฅผ ๋ง‰๋Š” ๋ฐ ํ•„์ˆ˜์ ์ž…๋‹ˆ๋‹ค[1][3].


์ œ์•ˆ ์‚ฌํ•ญ

  • ์ •์ฑ… ์—”์ง„(์˜ˆ: OPA, Open Policy Agent)์„ LLM ๋˜๋Š” Agent Runtime๊ณผ ์ง์ ‘ ์—ฐ๋™ํ•˜๊ณ , ๋ชจ๋“  ์‹คํ–‰ ์ด์ „์— ์ •์ฑ… ๊ฒฐ๊ณผ๋ฅผ ํ™•์ธํ•˜๋„๋ก ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค. OPA ๊ธฐ๋ฐ˜ ์ •์ฑ… ํ”„๋ ˆ์ž„์›Œํฌ๋Š” ์ด๋ฏธ ์—ฌ๋Ÿฌ AI-์—ฐ๋™ ์ธํ”„๋ผ์—์„œ ์„ ์ œ์  ์ •์ฑ… ํ•ด์„(PDP)๊ณผ ์‹คํ–‰ ๊ฒฐํ•ฉ(PEP) ์•„ํ‚คํ…์ฒ˜๋กœ ๊ฒ€์ฆ๋˜์—ˆ์Šต๋‹ˆ๋‹ค[3][12].
  • ์ •์ฑ… ํ…œํ”Œ๋ฆฟ๊ณผ ๋ฒ„์ „์„ ์ค‘์•™ ์ €์žฅ์†Œ(Central Policy Repository)์—์„œ ๊ด€๋ฆฌํ•˜๊ณ , ๋ชจ๋“  ๋…ธ๋“œ์— ์ฃผ๊ธฐ์ ์œผ๋กœ ๋ฐฐํฌ ๋ฐ ๊ฒ€์ฆํ•ฉ๋‹ˆ๋‹ค. ์ด ๋ฐฉ์‹์€ ๋ฒ„์ „ ๊ฐ„ ์ •์ฑ… ํ•ด์„ ์ฐจ์ด๋กœ ์ธํ•œ ๋น„๊ฒฐ์ •์„ฑ ๋ฌธ์ œ(T3)๋ฅผ ๋ฐฉ์ง€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค[4][14].
  • ์ •์ฑ… ๊ฒฐ๊ณผ(allow/deny)๊ฐ€ ํฌํ•จ๋œ ์‹คํ–‰ ์ „ ์„œ๋ช…๋œ ๊ฒฐ์ • ๊ฐ์ฒด(Policy Decision Token)๋ฅผ ์ƒ์„ฑํ•˜๊ณ , ์‹คํ–‰ ์—”์ง„์€ ํ•ด๋‹น ํ† ํฐ ์—†์ด ์ž‘๋™ํ•˜์ง€ ์•Š๋„๋ก ๊ฐ•์ œํ•ฉ๋‹ˆ๋‹ค. ์ด ๊ตฌ์กฐ๋Š” ์ •์ฑ…-์‹คํ–‰์˜ ๋…ผ๋ฆฌ์  ๊ฒฐ์†(Policy Binding)์„ ๋ณด์žฅํ•˜๋ฉฐ, ์‹คํ–‰ ๋กœ์ง ๋‹จ๋… ๊ฒฐ์ • ๊ตฌ์กฐ๋ฅผ ์ œ๊ฑฐํ•ฉ๋‹ˆ๋‹ค[10].

๊ธฐ๋Œ€ ํšจ๊ณผ

  • ์ •์ฑ… ์˜คํ•ด์„ ๋˜๋Š” ๋กœ์ปฌ ์ •์ฑ… ์ถฉ๋Œ๋กœ ์ธํ•œ ์˜ค์ž‘๋™ ๋ฐฉ์ง€
  • ์ •์ฑ…๊ณผ ์‹คํ–‰ ๊ฐ„ ๋ถˆ์ผ์น˜ ์ œ๊ฑฐ
  • ์‹œ์Šคํ…œ ์ „์ฒด์— ์ •์ฑ… ๊ธฐ๋ฐ˜ ํ†ต์ œ๋ ฅ ๊ฐ•ํ™”
  • ์œ„ํ˜‘ ์‹œ๋‚˜๋ฆฌ์˜ค C(๋™์ผ Context ํ•ด์„ ๋ถˆ์ผ์น˜) ๋ฐ ์‹œ๋‚˜๋ฆฌ์˜ค E(์ •์ฑ…-์‹คํ–‰ ๋ถ„๋ฆฌ)์— ๋Œ€ํ•œ ์„ ์ œ์  ๋Œ€์‘

๋Œ€์‘ ์œ„ํ˜‘

  • T2: ๊ถŒํ•œ ์œ„์ž„ ์‹œ ์ •์ฑ… ์ ์šฉ ๋ถˆ์ผ์น˜
  • T3: ์‹คํ–‰ ํ™˜๊ฒฝ ๊ฐ„ ์ •์ฑ… ํ•ด์„ ๋น„๊ฒฐ์ •์„ฑ

์ „๋žต B: ๋ฌธ๋งฅ ํ๋ฆ„์˜ ๋ฌด๊ฒฐ์„ฑ ๋ฐ ์œ„ยท๋ณ€์กฐ ๋ฐฉ์ง€

์ „๋žต ๋ชฉํ‘œ

MCP ๊ธฐ๋ฐ˜ ์‹œ์Šคํ…œ์—์„œ ๋ฌธ๋งฅ(Context)์€ ์‹คํ–‰์˜ ๊ธฐ์ค€์ด์ž, ์ •์ฑ… ํ•ด์„๊ณผ ๋ณด์•ˆ ํ†ต์ œ์˜ ํ•ต์‹ฌ ์š”์†Œ์ž…๋‹ˆ๋‹ค. ๋”ฐ๋ผ์„œ ์ „๋‹ฌ๋˜๋Š” Context Payload๊ฐ€ ์ค‘๊ฐ„์—์„œ ์กฐ์ž‘๋˜๊ฑฐ๋‚˜ ์œ„์กฐ๋˜๋Š” ๊ฒฝ์šฐ, ์ •์ฑ…์„ ์šฐํšŒํ•˜๊ฑฐ๋‚˜ LLM์˜ ์˜ค์ž‘๋™์„ ์œ ๋ฐœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋ณธ ์ „๋žต์€ Context ํ๋ฆ„์˜ ๋ฌด๊ฒฐ์„ฑ(Context Integrity)์„ ๋ณด์žฅํ•˜๊ณ , ์œ„ยท๋ณ€์กฐ(Tampering) ํ–‰์œ„๋ฅผ ์‹ค์‹œ๊ฐ„์œผ๋กœ ํƒ์ง€ ๋ฐ ์ฐจ๋‹จํ•˜๋Š” ๊ฒƒ์„ ๋ชฉํ‘œ๋กœ ํ•ฉ๋‹ˆ๋‹ค.


์ œ์•ˆ ์‚ฌํ•ญ

  • Context Payload์— ๋Œ€ํ•œ ๋””์ง€ํ„ธ ์„œ๋ช…(Signing)์„ ๋„์ž…ํ•˜์—ฌ, ๋ฌธ๋งฅ ์ƒ์„ฑ ์ฃผ์ฒด๊ฐ€ ์ธ์ฆ๋˜๊ณ  ๋‚ด์šฉ์ด ๋ณ€๊ฒฝ๋˜์ง€ ์•Š์•˜์Œ์„ ์ฆ๋ช…ํ•ฉ๋‹ˆ๋‹ค. ์„œ๋ช…์€ ๋น„๋Œ€์นญ ํ‚ค ๊ธฐ๋ฐ˜(PKI) ๋˜๋Š” HMAC ๊ธฐ๋ฐ˜ ์ธ์ฆ ๊ตฌ์กฐ๋กœ ๊ตฌํ˜„ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค[2][6].

  • ๊ฐ Context ํ๋ฆ„์— ๋Œ€ํ•ด ์ฒดํฌ์„ฌ ๋˜๋Š” ํ•ด์‹œ ํŠธ๋ฆฌ ๊ธฐ๋ฐ˜ ๋ฌด๊ฒฐ์„ฑ ์ •๋ณด(Context Integrity Hash)๋ฅผ ์ƒ์„ฑํ•˜๊ณ , MCP ์„œ๋ฒ„๊ฐ€ ์ด๋ฅผ ๊ฒ€์ฆํ•˜๋„๋ก ์„ค๊ณ„ํ•ฉ๋‹ˆ๋‹ค. Merkle Tree ๊ตฌ์กฐ๋ฅผ ์ ์šฉํ•˜๋ฉด ๋ณต์ˆ˜์˜ Context ํ•„๋“œ๋ฅผ ๋น ๋ฅด๊ฒŒ ๋น„๊ตํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์„ฑ๋Šฅ๊ณผ ์ •ํ™•์„ฑ์„ ๋™์‹œ์— ํ™•๋ณดํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค[3][12].

  • ์‹คํ–‰ ์‹œ์ ์—์„œ ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์ฆ์„ ํ†ต๊ณผํ•˜์ง€ ๋ชปํ•œ Context๋Š” ์ž๋™ ๊ฑฐ๋ถ€ํ•˜๋„๋ก ์ •์ฑ… ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. ๊ฒ€์ฆ ์‹คํŒจ ๋กœ๊ทธ๋Š” MCP ๊ฐ์‚ฌ ์‹œ์Šคํ…œ์œผ๋กœ ์ž๋™ ์ „์†ก๋˜๋ฉฐ, ๊ด€๋ฆฌ์ž ํ™•์ธ์„ ์š”๊ตฌํ•ฉ๋‹ˆ๋‹ค.

  • ์ด์ค‘ ์‹คํ–‰ ๊ฒฝ๋กœ(Double Context Validation) ์ „๋žต์„ ๋„์ž…ํ•˜์—ฌ, ์ •์ฑ… ์—”์ง„๊ณผ ์‹คํ–‰ ์—”์ง„ ์–‘์ชฝ์—์„œ ๋™์ผํ•œ ๋ฌธ๋งฅ์— ๋Œ€ํ•ด ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์‚ฌ๋ฅผ ์ˆ˜ํ–‰ํ•˜๋„๋ก ํ•ฉ๋‹ˆ๋‹ค. ์ด ๊ตฌ์กฐ๋Š” ์ค‘๊ฐ„ ๋…ธ๋“œ ๋˜๋Š” Agent์— ์˜ํ•œ ๋ฌธ๋งฅ ๋ณ€์กฐ ๊ฐ€๋Šฅ์„ฑ์„ ์›์ฒœ์ ์œผ๋กœ ์ฐจ๋‹จํ•ฉ๋‹ˆ๋‹ค [1][10].


๊ธฐ๋Œ€ ํšจ๊ณผ

  • Context ์˜ค์—ผ์„ ํ†ตํ•œ LLM ์˜ค์ž‘๋™ ์œ ๋ฐœ ์‹œ๋‚˜๋ฆฌ์˜ค(์‹œ๋‚˜๋ฆฌ์˜ค A) ๋ฐฉ์ง€
  • ์ •์ฑ… ์šฐํšŒ, ๊ถŒํ•œ ์œ„์žฅ ๋“ฑ ๋ฌธ๋งฅ ์กฐ์ž‘ ๊ธฐ๋ฐ˜ ๊ณต๊ฒฉ ์ฐจ๋‹จ
  • ๋ฌธ๋งฅ ๊ธฐ๋ฐ˜ ์˜์‚ฌ๊ฒฐ์ •์˜ ์‹ ๋ขฐ๋„ ํ™•๋ณด
  • Context ๋ฌด๊ฒฐ์„ฑ ๊ธฐ๋ฐ˜ ๊ฐ์‚ฌ ๋กœ๊ทธ ๊ตฌ์ถ• ๊ฐ€๋Šฅ

๋Œ€์‘ ์œ„ํ˜‘

  • T1: ๋ฌธ๋งฅ ์ฃผ์ž… ๋ฐ ์กฐ์ž‘(Context Injection)
  • T3: ๋ฌธ๋งฅ ๊ธฐ๋ฐ˜ ํ–‰๋™ ์กฐ์ž‘(Model Misbehavior from Context Distortion)

์ „๋žต C: ๊ถŒํ•œ ์œ„์ž„ ํ†ต์ œ ๋ฐ ์‚ฌ์นญ ๋ฐฉ์ง€

์ „๋žต ๋ชฉํ‘œ

MCP ์‹œ์Šคํ…œ์€ ๋‹ค์–‘ํ•œ ์—์ด์ „ํŠธ๊ฐ€ ํ˜‘์—…ํ•˜๋Š” ๊ตฌ์กฐ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•˜๋ฉฐ, ์ด ๊ณผ์ •์—์„œ ๊ถŒํ•œ ์œ„์ž„(Delegation)์ด ๋นˆ๋ฒˆํžˆ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์œ„์ž„ ์š”์ฒญ์— ๋Œ€ํ•œ ๊ฒ€์ฆ์ด ์ถฉ๋ถ„ํ•˜์ง€ ์•Š์„ ๊ฒฝ์šฐ, ๊ณต๊ฒฉ์ž๋Š” ์œ„์ž„ ์š”์ฒญ์„ ์‚ฌ์นญํ•˜๊ฑฐ๋‚˜ ์œ„์ž„ ์ฒด๊ณ„๋ฅผ ์˜ค์šฉํ•˜์—ฌ ๋น„์ธ๊ฐ€ ๊ถŒํ•œ ์ƒ์Šน(Unauthorized Privilege Escalation)์„ ์œ ๋ฐœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ „๋žต์€ ์œ„์ž„ ์ฒด๊ณ„๋ฅผ ๋ช…์‹œ์ ์ด๊ณ  ์ œํ•œ์ ์œผ๋กœ ์„ค๊ณ„ํ•˜๊ณ , ์œ„์ž„ ๊ฒฝ๋กœ์˜ ์ถ”์  ๊ฐ€๋Šฅ์„ฑ(Delegation Traceability)์„ ํ™•๋ณดํ•˜๋Š” ๋ฐ ๋ชฉ์ ์ด ์žˆ์Šต๋‹ˆ๋‹ค.


์ œ์•ˆ ์‚ฌํ•ญ

  • ๋ชจ๋“  ์œ„์ž„ ์š”์ฒญ์—๋Š” ์œ„์ž„ ์‚ฌ์Šฌ(delegation chain) ์ •๋ณด๊ฐ€ ํฌํ•จ๋˜์–ด์•ผ ํ•˜๋ฉฐ, ์ด์ „ ์œ„์ž„์ž์˜ ID, ์ •์ฑ… ์Šน์ธ ๋‚ด์—ญ, ์„œ๋ช… ์ •๋ณด๋ฅผ ํ•จ๊ป˜ ์ „๋‹ฌํ•ฉ๋‹ˆ๋‹ค. ์œ„์ž„ ์‚ฌ์Šฌ์€ OIDC ๊ธฐ๋ฐ˜ ํ† ํฐ ์ฒด๊ณ„ ๋˜๋Š” MCP ์ž์ฒด์˜ Context ์ฒด๊ณ„์— ํฌํ•จ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค[2][10].

  • ์œ„์ž„ ๋ฒ”์œ„๋ฅผ ์ •์˜ํ•˜๋Š” scope ๋˜๋Š” capability ํ•„๋“œ์— ๋Œ€ํ•ด ์ƒํ•œ ์ œํ•œ(Delegation Scope Ceiling)์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. ์˜ˆ: "read-only" ์—ญํ• ์€ ์ ˆ๋Œ€๋กœ "admin-level delegation" ์š”์ฒญ์„ ํฌํ•จํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. ์ด ์›์น™์€ RBAC์™€ ๋น„์Šทํ•œ ๋ฐฉ์‹์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค[11].

  • MCP ์„œ๋ฒ„ ๋˜๋Š” ์ •์ฑ… ์—”์ง„์€ ์œ„์ž„ ์š”์ฒญ ์ˆ˜์‹  ์‹œ, ํ•ด๋‹น ์œ„์ž„์ด ์ •์ฑ…์— ๋“ฑ๋ก๋œ ์œ„์ž„ ๊ฒฝ๋กœ(policy-authorized path)์™€ ์ผ์น˜ํ•˜๋Š”์ง€ ๊ฒ€์ฆํ•ฉ๋‹ˆ๋‹ค. ํ—ˆ์šฉ๋˜์ง€ ์•Š์€ ์œ„์ž„ ์ฒด๊ณ„๊ฐ€ ๋ฐœ๊ฒฌ๋˜๋ฉด ์ฆ‰์‹œ ์ฐจ๋‹จ๋˜๋ฉฐ, ์œ„์ž„๋œ ์—ญํ• ์€ ์‹คํ–‰๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

  • ์œ„์ž„ ์š”์ฒญ์˜ ์ง„์œ„ ์—ฌ๋ถ€ ํ™•์ธ์„ ์œ„ํ•œ ์„œ๋ช… ๊ฒ€์ฆ(Signature Verification)์„ ํ•„์ˆ˜ํ™”ํ•ฉ๋‹ˆ๋‹ค. ์œ„์ž„ ์š”์ฒญ์„ ๋ฐœ๊ธ‰ํ•œ ์ฃผ์ฒด๊ฐ€ ์‹ค์ œ๋กœ ์„œ๋ช…ํ•œ ๊ฒƒ์ธ์ง€๋ฅผ ์ฒดํฌํ•˜๋ฉฐ, MAC ๋˜๋Š” RSA ๊ธฐ๋ฐ˜ ์„œ๋ช…์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค[6].


๊ธฐ๋Œ€ ํšจ๊ณผ

  • ์‚ฌ์นญ๋œ ์—์ด์ „ํŠธ์˜ ์œ„์ž„ ์š”์ฒญ ์ฐจ๋‹จ
  • ๊ถŒํ•œ ๋ฒ”์œ„๋ฅผ ์ดˆ๊ณผํ•œ ๊ณผ๋„ํ•œ ์œ„์ž„ ์š”์ฒญ ์ œ์–ด
  • ์œ„์ž„ ์‹คํ–‰ ์‹œ ์ถ”์  ๊ฐ€๋Šฅํ•œ ์‹ ๋ขฐ ์ฒด์ธ ํ™•๋ณด
  • ๊ณต๊ฒฉ์ž๊ฐ€ ํ•˜์œ„ ์—์ด์ „ํŠธ๋ฅผ ํ†ตํ•ด ์ƒ์œ„ ๊ถŒํ•œ์„ ํƒˆ์ทจํ•˜๋Š” T2 ์‹œ๋‚˜๋ฆฌ์˜ค ๋ฐฉ์–ด

๋Œ€์‘ ์œ„ํ˜‘

  • T2: ๊ถŒํ•œ ์œ„์ž„ ์˜ค์šฉ ๋ฐ ์‚ฌ์นญ ์œ„์ž„ ์š”์ฒญ(Delegation Abuse)

์ „๋žต D: ๊ฐ์‚ฌ ๋กœ๊ทธ ๊ตฌ์กฐํ™” ๋ฐ ํฌ๋ Œ์‹ ์ถ”์ ์„ฑ ๊ฐ•ํ™”

์ „๋žต ๋ชฉํ‘œ

MCP ๊ธฐ๋ฐ˜ ์‹œ์Šคํ…œ์˜ ๋ณด์•ˆ์„ฑ์„ ์œ ์ง€ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ๋ฌธ๋งฅ ํ๋ฆ„, ์ •์ฑ… ํŒ๋‹จ, ์‹คํ–‰ ๊ฒฐ๊ณผ์— ๋Œ€ํ•œ ์ฒด๊ณ„์  ๊ธฐ๋ก์ด ํ•„์ˆ˜์ ์ž…๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ๋น„ํ‘œ์ค€ ํฌ๋งท์˜ ๋กœ๊ทธ, ์ผ๋ถ€ ๋ˆ„๋ฝ๋œ ์ด๋ฒคํŠธ ๊ธฐ๋ก, ์—์ด์ „ํŠธ ๊ฐ„์˜ ๋น„์—ฐ๊ณ„ ๋กœ๊ทธ ๊ตฌ์กฐ๋Š” ๊ฐ์‚ฌ ๋ถˆ๊ฐ€๋Šฅ์„ฑ(Audit Invisibility)์„ ์œ ๋ฐœํ•˜๋ฉฐ, ์ด๋Š” ์นจํ•ด ์‚ฌ๊ณ  ๋ฐœ์ƒ ์‹œ ์›์ธ ๋ถ„์„ ๋ถˆ๊ฐ€, ์ฑ…์ž„ ์ถ”์  ์‹คํŒจ, ๊ทœ์ œ ๋Œ€์‘ ์ง€์—ฐ ๋“ฑ์˜ ๋ฆฌ์Šคํฌ๋กœ ์—ฐ๊ฒฐ๋ฉ๋‹ˆ๋‹ค. ๋ณธ ์ „๋žต์€ ๋กœ๊ทธ ๊ธฐ๋ก์„ ํ‘œ์ค€ํ™”๋œ ๊ตฌ์กฐ(Structured Logging Format)๋กœ ํ†ต์ผํ•˜๊ณ , ์‚ฌํ›„ ์ถ”์ ์ด ๊ฐ€๋Šฅํ•œ ์ด๋ฒคํŠธ ์—ฐ๊ณ„ ์‹œ์Šคํ…œ์„ ๊ตฌ์ถ•ํ•˜์—ฌ ํฌ๋ Œ์‹ ๊ธฐ๋ฐ˜ ์‚ฌ๊ณ  ๋Œ€์‘ ์ฒด๊ณ„(Security Forensics Readiness)๋ฅผ ๊ฐ•ํ™”ํ•˜๋Š” ๊ฒƒ์„ ๋ชฉํ‘œ๋กœ ํ•ฉ๋‹ˆ๋‹ค.

์ œ์•ˆ ์‚ฌํ•ญ

  • ๋ชจ๋“  MCP ๊ด€๋ จ ์‹คํ–‰์€ Context ID, Agent ID, ์‹คํ–‰ ์ •์ฑ…, ์‹œ๊ฐ„, ๊ฒฐ๊ณผ, ์„œ๋ช… ์—ฌ๋ถ€๋ฅผ ํฌํ•จํ•˜๋Š” ๊ตฌ์กฐํ™”๋œ JSON ๋กœ๊ทธ๋กœ ๊ธฐ๋กํ•ฉ๋‹ˆ๋‹ค. ์ด ๊ตฌ์กฐ๋Š” MCP Server, Policy Engine, Execution Layer ๊ฐ„ ๊ณตํ†ต ํฌ๋งท์œผ๋กœ ์ •์˜๋ฉ๋‹ˆ๋‹ค[2][12].

  • ๊ฐ ๋กœ๊ทธ ํ•ญ๋ชฉ์—๋Š” ์„œ๋ช… ๋˜๋Š” ํ•ด์‹œ๊ฐ’(Log Hashing / Signing)์ด ํฌํ•จ๋˜์–ด, ์œ„ยท๋ณ€์กฐ ์—ฌ๋ถ€๋ฅผ ํŒ๋‹จํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ฉ๋‹ˆ๋‹ค. Merkle Tree ๋˜๋Š” SHA256 ๊ธฐ๋ฐ˜ ํ•ด์‹œ ์ฒด๊ณ„๋ฅผ ํ™œ์šฉํ•˜๋ฉฐ, ๋กœ๊ทธ ์—ฐ๊ณ„ ์ถ”์ ์„ ์œ„ํ•œ prev_hash, session_id ํ•„๋“œ๋ฅผ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค[6][13].

  • ์ค‘๊ฐ„ ๋…ธ๋“œ๋‚˜ Relay Agent์— ์˜ํ•œ ์ด๋ฒคํŠธ ์ „ํŒŒ(log propagation)๋„ ์ค‘์•™ ๊ฐ์‚ฌ ์„œ๋ฒ„์— ๊ธฐ๋ก๋˜๋„๋ก ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. ์ด๋ฅผ ํ†ตํ•ด Context ์ด๋™ ๊ฒฝ๋กœ(Flow Path)์™€ ์‹คํ–‰ Agent ๊ฐ„ ์‹ ๋ขฐ ๊ฒฝ๋กœ๊ฐ€ ํŒŒ์•…๋ฉ๋‹ˆ๋‹ค.

  • SIEM(Security Information and Event Management) ๋˜๋Š” Forensic Tool๊ณผ์˜ ์‹ค์‹œ๊ฐ„ ์—ฐ๋™์„ ํ†ตํ•ด, ์œ„ํ˜‘ ํƒ์ง€์™€ ์‚ฌ๊ณ  ์žฌํ˜„์„ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค. ํ•„์š” ์‹œ KQL/SQL ๊ธฐ๋ฐ˜ ํƒ์ƒ‰ ์ฟผ๋ฆฌ๋ฅผ ์ž๋™ ์ƒ์„ฑํ•  ์ˆ˜ ์žˆ๋Š” ๋กœ๊ทธ ๊ตฌ์กฐ ์„ค๊ณ„๋ฅผ ์ ์šฉํ•ฉ๋‹ˆ๋‹ค[4].


๊ธฐ๋Œ€ ํšจ๊ณผ

  • ๋ชจ๋“  ๋ฌธ๋งฅ ํ๋ฆ„์— ๋Œ€ํ•œ ๊ฐ์‹œ ๊ฐ€๋Šฅ์„ฑ ํ™•๋ณด
  • ์œ„์กฐ ๋˜๋Š” ์‚ฌ์นญ ์š”์ฒญ์— ๋Œ€ํ•œ ์‚ฌํ›„ ์ถ”์  ๋ฐ ์ฑ…์ž„์ž ์‹๋ณ„ ๊ฐ€๋Šฅ
  • ๊ฐ์‚ฌ ๋ฐ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ฐ์‚ฌ ๋Œ€์‘ ์ฒด๊ณ„ ๊ฐ•ํ™”
  • T4 ์‹œ๋‚˜๋ฆฌ์˜ค(์‚ฌ๊ณ  ์ถ”์  ์‹คํŒจ)์— ๋Œ€ํ•œ ์ง์ ‘์ ์ธ ๋ฐฉ์–ด ์ˆ˜๋‹จ ์ œ๊ณต

๋Œ€์‘ ์œ„ํ˜‘

  • T4: ๋ฌธ๋งฅ ํ๋ฆ„์˜ ๋กœ๊น… ๋ˆ„๋ฝ, ๊ฐ์‚ฌ ๋ถˆ๊ฐ€์„ฑ

์ด ์ „๋žต์€ ๋‹จ์ˆœ ๊ธฐ๋ก ๊ธฐ๋Šฅ์ด ์•„๋‹ˆ๋ผ, ๋ณด์•ˆ ์šด์˜ํŒ€์ด MCP ๊ธฐ๋ฐ˜ ์‹œ์Šคํ…œ์˜ ๋‚ด๋ถ€ ํ™œ๋™์„ ํˆฌ๋ช…ํ•˜๊ฒŒ ํŒŒ์•…ํ•˜๊ณ  ๋Œ€์‘ํ•  ์ˆ˜ ์žˆ๋Š” ์ •๋ณด ๊ธฐ๋ฐ˜์„ ์ œ๊ณตํ•˜๋ฉฐ, ๊ฐ์‚ฌ ๊ฐ€๋Šฅ์„ฑ(Auditability)๊ณผ ์‚ฌ๊ณ  ๋ณต์›๋ ฅ(Resilience)์„ ๋™์‹œ์— ํ™•๋ณดํ•ฉ๋‹ˆ๋‹ค[12][13][15].

์ „๋žต ์ข…ํ•ฉ ์š”์•ฝํ‘œ

MCP ๋ณด์•ˆ ์œ„ํ˜‘ ๋Œ€์‘์„ ์œ„ํ•œ 4๋Œ€ ์ „๋žต ์š”์•ฝํ‘œ

์ „๋žต ๋ฒˆํ˜ธ์ „๋žต๋ช…ํ•ต์‹ฌ ๋‚ด์šฉ ์š”์•ฝ๋Œ€์‘ ์œ„ํ˜‘
์ „๋žต A์ •์ฑ… ์ผ๊ด€์„ฑ ํ™•๋ณด ๋ฐ ์‹คํ–‰ ์—ฐ๋™์ •์ฑ… ํ•ด์„ ๊ฒฐ๊ณผ๋ฅผ ์‹คํ–‰ ์ „์— ๊ฐ•์ œ ๋ฐ˜์˜ํ•˜์—ฌ ์‹คํ–‰ ์—”์ง„๊ณผ ์ •์ฑ… ๊ฐ„ ์ผ๊ด€์„ฑ์„ ์œ ์ง€T2, T3
์ „๋žต B๋ฌธ๋งฅ ํ๋ฆ„์˜ ๋ฌด๊ฒฐ์„ฑ ๋ฐ ์œ„ยท๋ณ€์กฐ ๋ฐฉ์ง€Context ์ „๋‹ฌ ์‹œ ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์ฆ ๋ฐ ๋””์ง€ํ„ธ ์„œ๋ช… ์ ์šฉ์œผ๋กœ ๋ฌธ๋งฅ ์กฐ์ž‘ ๋ฐฉ์ง€T1
์ „๋žต C๊ถŒํ•œ ์œ„์ž„ ํ†ต์ œ ๋ฐ ์‚ฌ์นญ ๋ฐฉ์ง€์œ„์ž„ ์ฒด์ธ ์ถ”์ , ๋ฒ”์œ„ ์ œํ•œ ๋ฐ ์„œ๋ช… ๊ฒ€์ฆ์„ ํ†ตํ•ด ์œ„์ž„ ์š”์ฒญ์˜ ๋ฌด๊ฒฐ์„ฑ๊ณผ ์ •๋‹น์„ฑ ํ™•๋ณดT2
์ „๋žต D๊ฐ์‚ฌ ๋กœ๊ทธ ๊ตฌ์กฐํ™” ๋ฐ ํฌ๋ Œ์‹ ์ถ”์ ์„ฑ ๊ฐ•ํ™”Context ํ๋ฆ„๊ณผ ์‹คํ–‰ ๊ฒฐ๊ณผ๋ฅผ ๊ตฌ์กฐํ™”๋œ ํฌ๋งท์œผ๋กœ ๊ธฐ๋กํ•˜๊ณ , ๊ฐ์‚ฌ ๊ฐ€๋Šฅ์„ฑ์„ ํ™•๋ณดT4

๋‹ค์Œ์€ ๋งˆ์ง€๋ง‰ ์„น์…˜์ธ 5: ๊ฒฐ๋ก  ๋ฐ ์ƒˆ๋กœ์šด ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜ ์ œ์•ˆ์ž…๋‹ˆ๋‹ค. ์ด ํŒŒํŠธ์—์„œ๋Š” ์•ž์„œ ๋…ผ์˜๋œ ์œ„ํ˜‘๊ณผ ์ „๋žต์„ ๊ธฐ๋ฐ˜์œผ๋กœ, MCP ๊ธฐ๋ฐ˜ AI ์‹œ์Šคํ…œ์— ์š”๊ตฌ๋˜๋Š” ์‹ ๊ทœ ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜์˜ ํ•„์š”์„ฑ๊ณผ ๋ฐฉํ–ฅ์„ฑ์„ ์ œ์•ˆํ•ฉ๋‹ˆ๋‹ค.

5. ๊ฒฐ๋ก  ๋ฐ ์ƒˆ๋กœ์šด ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜ ์ œ์•ˆ

๋ถ„์„ ์ข…ํ•ฉ

๋ณธ ๋ฐฑ์„œ์—์„œ๋Š” ์ด 15ํŽธ์˜ ์ตœ์‹  ๋ฌธํ—Œ์„ ๊ธฐ๋ฐ˜์œผ๋กœ, MCP(Model Context Protocol)๋ฅผ ์ค‘์‹ฌ์œผ๋กœ ์ž‘๋™ํ•˜๋Š” AI ์‹œ์Šคํ…œ ๋‚ด ๋ณด์•ˆ ์œ„ํ˜‘์„ ๊ตฌ์กฐ์ ์œผ๋กœ ๋ถ„์„ํ•˜์˜€์Šต๋‹ˆ๋‹ค. ๋ฌธ๋งฅ ์ „๋‹ฌ, ์ •์ฑ… ํ•ด์„, ์‹คํ–‰ ์ œ์–ด, ๊ฐ์‚ฌ ํ๋ฆ„ ๋“ฑ ๋‹ค์–‘ํ•œ ๊ณ„์ธต์—์„œ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋„ค ๊ฐ€์ง€ ํ•ต์‹ฌ ์œ„ํ˜‘ ์œ ํ˜•์ด ๋ฐ˜๋ณต์ ์œผ๋กœ ๊ด€์ฐฐ๋˜์—ˆ์Šต๋‹ˆ๋‹ค:

  • T1: ๋ฌธ๋งฅ ์กฐ์ž‘ ๋ฐ ์ฃผ์ž…(Context Injection)
  • T2: ๊ถŒํ•œ ์œ„์ž„์˜ ์˜ค๋‚จ์šฉ(Delegation Abuse)
  • T3: ์ •์ฑ… ํŒ๋‹จ ๋ฐ ์‹คํ–‰ ๊ฒฐ๊ณผ์˜ ๋น„๊ฒฐ์ •์„ฑ(Non-deterministic Execution)
  • T4: ๊ฐ์‚ฌ ๋ถˆ๊ฐ€๋Šฅ์„ฑ๊ณผ ํฌ๋ Œ์‹ ์‹คํŒจ(Audit Invisibility)

์ด๋Ÿฌํ•œ ์œ„ํ˜‘๋“ค์€ MCP ๊ธฐ๋ฐ˜ AI ์ธํ”„๋ผ์˜ ์‹ ๋ขฐ์„ฑ(Reliability), ์ฑ…์ž„์„ฑ(Accountability), ์ •์ฑ… ์ผ๊ด€์„ฑ(Consistency)์„ ์‹ฌ๊ฐํ•˜๊ฒŒ ํ›ผ์†ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ๊ธฐ์กด ๋ณด์•ˆ ์ฒด๊ณ„๋งŒ์œผ๋กœ๋Š” ์ถฉ๋ถ„ํ•œ ๋ฐฉ์–ด๊ฐ€ ์–ด๋ ต์Šต๋‹ˆ๋‹ค.

๊ธฐ์กด ์ „๋žต์˜ ๊ธฐ๋ฐ˜๊ณผ ํ™•์žฅ ๋ฐฉํ–ฅ

Section 4์—์„œ๋Š” MCP ๋ณด์•ˆ ์œ„ํ˜‘(T1~T4)์— ๋Œ€์‘ํ•˜๊ธฐ ์œ„ํ•œ 4๊ฐ€์ง€ ์ „๋žต์„ ์ œ์‹œํ•˜์˜€์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์ „๋žต์€ ๋ฌธ๋งฅ ๋ฌด๊ฒฐ์„ฑ, ๊ถŒํ•œ ์œ„์ž„ ํ†ต์ œ, ์ •์ฑ… ์‹คํ–‰ ์ผ๊ด€์„ฑ, ๊ฐ์‚ฌ ์ถ”์ ์„ฑ ๋“ฑ์˜ ์ธก๋ฉด์—์„œ ์œ„ํ˜‘ ์‹œ๋‚˜๋ฆฌ์˜ค์— ๋Œ€์‘ํ•  ์ˆ˜ ์žˆ๋Š” ์„ค๊ณ„ ์›์น™์œผ๋กœ ๋งค์šฐ ์œ ํšจํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์ด ์ „๋žต๋“ค์ด ํ˜„์‹ค์˜ AI ๊ธฐ๋ฐ˜ ์ธํ”„๋ผ์—์„œ ์ง€์†์ ์ด๊ณ  ์ผ๊ด€๋˜๊ฒŒ ์ ์šฉ๋˜๊ธฐ ์œ„ํ•ด์„œ๋Š”, ๋‹จ์ผ ๊ธฐ๋Šฅ์ด๋‚˜ ๊ฐœ๋ณ„ ๊ตฌ์„ฑ์š”์†Œ ์ˆ˜์ค€์„ ๋„˜์–ด์„  ํ†ตํ•ฉ๋œ ์‹คํ–‰ ๊ตฌ์กฐ๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ์ฆ‰, ์ „๋žต์˜ ์œ ํšจ์„ฑ ์ž์ฒด๊ฐ€ ์•„๋‹ˆ๋ผ, ๊ทธ๊ฒƒ์„ ์ž๋™ํ™”๋˜๊ณ  ์‹ ๋ขฐ ๊ฐ€๋Šฅํ•œ ๋ฐฉ์‹์œผ๋กœ ์šด์˜ํ•  ์ˆ˜ ์žˆ๋Š” ๋ณด์•ˆ ํ”„๋ ˆ์ž„์›Œํฌ๊ฐ€ ์š”๊ตฌ๋˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ํŠนํžˆ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์š”๊ตฌ๋Š” ๊ทธ๋Ÿฌํ•œ ํ”„๋ ˆ์ž„์›Œํฌ์˜ ํ•„์š”์„ฑ์„ ๋”์šฑ ๋ช…ํ™•ํžˆ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค:

  • ์ •์ฑ… ํ•ด์„๊ณผ ์‹คํ–‰ ๊ฐ„์˜ ๊ฐ•์ œ ์—ฐ๋™ ๊ตฌ์กฐ ํ•„์š” (Policy Evaluationโ€“Execution Binding with Enforcement)

  • ์œ„์ž„ ์š”์ฒญ ํ๋ฆ„์— ๋Œ€ํ•œ ์ถ”์  ๊ฐ€๋Šฅ์„ฑ๊ณผ ์ œํ•œ ์„ค์ • (Delegation Chain Tracking and Scoped Control)

  • ๋ฌธ๋งฅ ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์ฆ ๋ฐ ์ •์ฑ… ์ ์šฉ ๊ฒฐ๊ณผ ์‚ฌ์ „ ๊ฒ€์ฆ (Context Integrity Validation and Pre-execution Policy Binding)

  • ์‹คํ–‰ ํ๋ฆ„๊ณผ ์ •์ฑ… ํŒ๋‹จ ๊ฒฐ๊ณผ์˜ ๊ตฌ์กฐํ™”๋œ ๊ฐ์‚ฌ ๊ธฐ๋ก ๋ณด์žฅ (Structured and Signed Audit Logging of Execution and Policy Results)

  • ์œ„ํ—˜ ์ ์ˆ˜ ๊ธฐ๋ฐ˜์˜ ์ž์œจ ์ ‘๊ทผ ์ œ์–ด ์ •์ฑ… ์ ์šฉ ํ•„์š” (Risk-adaptive Autonomous Access Control)

์ด๋Ÿฌํ•œ ์š”๊ตฌ์‚ฌํ•ญ์€ ๋‹จ์ˆœ ๊ธฐ๋Šฅ์ด ์•„๋‹Œ, ๋ณด์•ˆ ์ „๋žต์„ ์ผ๊ด€๋˜๊ฒŒ ๊ตฌํ˜„ํ•˜๊ณ  ์šด์˜ํ•  ์ˆ˜ ์žˆ๋Š” ๊ธฐ๋ฐ˜ ์ฒด๊ณ„๋ฅผ ์˜๋ฏธํ•˜๋ฉฐ, ์ด๋ฅผ ์œ„ํ•ด ๋ณธ ๋ฐฑ์„œ๋Š” MCP PAM (Model Context Protocol Privileged Access Management)์ด๋ผ๋Š” MCP ํŠนํ™” ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜ ์†”๋ฃจ์…˜์„ ์ œ์•ˆํ•ฉ๋‹ˆ๋‹ค. ์•„๋ž˜๋Š” ์•ž์„œ ์ •๋ฆฌ๋œ 5.2 ํ•ญ๋ชฉ์˜ ํ๋ฆ„์— ๋งž์ถฐ ๊ตฌ์„ฑ๋œ 5.3: ์ƒˆ๋กœ์šด ๋ณด์•ˆ ํ”„๋ ˆ์ž„์›Œํฌ์˜ ํ•„์š” โ€“ MCP PAM ์ œ์•ˆ์ž…๋‹ˆ๋‹ค. MCP PAM์˜ ํ•ต์‹ฌ ๊ธฐ๋Šฅ์„ ์ •๋ฆฌํ•˜๊ณ , T1~T4 ์œ„ํ˜‘ ๋Œ€์‘ ๊ด€๊ณ„๋ฅผ ๋ช…ํ™•ํ•˜๊ฒŒ ๋งคํ•‘ํ•˜์—ฌ ์ œ์•ˆํ•˜๋Š” ๋‚ด์šฉ์œผ๋กœ ๊ตฌ์„ฑ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

์ƒˆ๋กœ์šด ๋ณด์•ˆ ํ”„๋ ˆ์ž„์›Œํฌ์˜ ํ•„์š”: MCP PAM ์ œ์•ˆ

MCP PAM, ์ฆ‰ Model Context Protocol Privileged Access Management๋Š” MCP ๊ธฐ๋ฐ˜ ์‹œ์Šคํ…œ์—์„œ ๋ฐœ์ƒํ•˜๋Š” ์œ„ํ˜‘ ์‹œ๋‚˜๋ฆฌ์˜ค(T1~T4)์— ์‹ค์งˆ์ ์œผ๋กœ ๋Œ€์‘ํ•˜๊ธฐ ์œ„ํ•ด ์„ค๊ณ„๋œ MCP Security ์•„ํ‚คํ…์ฒ˜์ž…๋‹ˆ๋‹ค. MCP PAM์€ ๋‹จ์ˆœํ•œ ๊ถŒํ•œ ๊ด€๋ฆฌ ๋„๊ตฌ๊ฐ€ ์•„๋‹ˆ๋ผ, ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๊ธฐ๋Šฅ์„ ๊ฐ–์ถ˜ ๋ฌธ๋งฅ ์ธ์ง€ํ˜•(Context-Aware), ์ •์ฑ… ์—ฐ๋™ํ˜•(Policy-Enforced), ์ž์œจ ํŒ๋‹จํ˜•(Risk-Adaptive) ๋ณด์•ˆ ํ”Œ๋žซํผ์ž…๋‹ˆ๋‹ค.

MCP PAM์˜ ํ•ต์‹ฌ ๊ธฐ๋Šฅ ์š”์•ฝ

MCP PAM ๊ธฐ๋Šฅ (Capability)์„ค๋ช…
Context-aware Access Control
๋ฌธ๋งฅ ์ธ์ง€ ๊ธฐ๋ฐ˜ ์ ‘๊ทผ ์ œ์–ด
์‹คํ–‰ ๋ฌธ๋งฅ์— ๋”ฐ๋ผ ์ •์ฑ…์„ ๋™์ ์œผ๋กœ ํ‰๊ฐ€ํ•˜๊ณ , ์ƒํ™ฉ์— ๋งž๋Š” ์ ‘๊ทผ์„ ํ—ˆ์šฉ ๋˜๋Š” ์ฐจ๋‹จ
Delegation Chain Verification
์œ„์ž„ ์ฒด์ธ ๊ฒ€์ฆ ๋ฐ ์ถ”์ 
์œ„์ž„ ์š”์ฒญ์˜ ์œ ํšจ์„ฑ, ์ฒด๊ณ„, ๋ฒ”์œ„๋ฅผ ์ •์ฑ… ๊ธฐ๋ฐ˜์œผ๋กœ ํ‰๊ฐ€ํ•˜๊ณ  ์œ„์กฐ/์‚ฌ์นญ์„ ๋ฐฉ์ง€
Policy-Bound Execution Enforcement
์ •์ฑ…-์‹คํ–‰ ๊ฐ•์ œ ์—ฐ๋™
์ •์ฑ… ํŒ๋‹จ ๊ฒฐ๊ณผ๊ฐ€ ์‹ค์ œ ์‹คํ–‰ ํ๋ฆ„์— ๋ฐ˜์˜๋˜์ง€ ์•Š์œผ๋ฉด ์š”์ฒญ ์ž์ฒด๋ฅผ ์ฐจ๋‹จ
Structured & Signed Logging
์„œ๋ช… ๊ธฐ๋ฐ˜ ๊ฐ์‚ฌ ๋กœ๊ทธ ๊ตฌ์กฐํ™”
์‹คํ–‰, ์ •์ฑ…, Context๋ฅผ ํ†ตํ•ฉ ๊ธฐ๋กํ•˜๊ณ , ๋ฌด๊ฒฐ์„ฑ์„ ํ•ด์‹œ/์„œ๋ช…์œผ๋กœ ๋ณด์žฅ
Risk-Adaptive Autonomous Control
์œ„ํ—˜ ๊ธฐ๋ฐ˜ ์ž์œจ ์ •์ฑ… ์ ์šฉ
DLP ๋ฐ UEBA์˜ ์œ„ํ—˜ ์ ์ˆ˜๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ์‹คํ–‰์„ ์‹ค์‹œ๊ฐ„ ์กฐ์ •ํ•˜๊ณ , ์ •์ฑ…์„ ์ž๋™ ์ ์šฉ

MCP PAM ๊ธฐ๋Šฅ๊ณผ ๋ณด์•ˆ ์œ„ํ˜‘(T1~T4) ๋Œ€์‘ ๋งคํ•‘ (โ— ์ง์ ‘ ๋Œ€์‘ | โ—‹ ๊ฐ„์ ‘ ๋Œ€์‘)

MCP PAM ๊ธฐ๋Šฅ (Capability)T1: ๋ฌธ๋งฅ ์กฐ์ž‘
(Context Injection)
T2: ์œ„์ž„ ์˜ค๋‚จ์šฉ
(Delegation Abuse)
T3: ์‹คํ–‰ ๋ถˆ์ผ์น˜
(Execution Inconsistency)
T4: ๊ฐ์‚ฌ ๋ถˆ๊ฐ€์„ฑ
(Audit Invisibility)
Context-aware Access Control / ๋ฌธ๋งฅ ์ธ์ง€ ์ ‘๊ทผ ์ œ์–ดโ—โ—‹โ—
Delegation Chain Verification / ์œ„์ž„ ์ฒด์ธ ๊ฒ€์ฆ ๋ฐ ์ถ”์ โ—โ—‹
Policy-Bound Execution Enforcement / ์ •์ฑ…-์‹คํ–‰ ๊ฐ•์ œ ์—ฐ๋™โ—‹โ—โ—
Structured & Signed Logging / ์„œ๋ช… ๊ธฐ๋ฐ˜ ๊ฐ์‚ฌ ๋กœ๊ทธ ๊ตฌ์กฐํ™”โ—‹โ—
Risk-Adaptive Autonomous Control / ์œ„ํ—˜ ๊ธฐ๋ฐ˜ ์ž์œจ ์ •์ฑ… ์ ์šฉโ—โ—โ—โ—‹

๋˜ํ•œ, MCP PAM์€ MCP ํ™˜๊ฒฝ์˜ ๋ณด์•ˆ ์œ„ํ˜‘์— ๋Œ€ํ•ด ๋‹ค์Œ๊ณผ ๊ฐ™์€ ํŠน์„ฑ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค:

  • ์˜ˆ๋ฐฉ(Preventive): ์‹คํ–‰ ์ „ ์ •์ฑ… ํ™•์ธ, ๋ฌธ๋งฅ ์œ„ยท๋ณ€์กฐ ๋ฐฉ์ง€
  • ํƒ์ง€(Detective): ์‹ค์‹œ๊ฐ„ ๋กœ๊น… ๋ฐ ์œ„ํ˜‘ ์ ์ˆ˜ ๋ถ„์„
  • ๋Œ€์‘(Responsive): ์ž์œจ ์ •์ฑ… ์ „ํ™˜ ๋ฐ ์‹คํ–‰ ์ฐจ๋‹จ
  • ์ถ”์ (Accountable): ์‹คํ–‰ ํ๋ฆ„ ์ „์ฒด๋ฅผ ๊ฐ์‚ฌ ๊ฐ€๋Šฅํ•œ ํ˜•ํƒœ๋กœ ๊ธฐ๋ก

MCP PAM์€ ์ •์ฑ…๊ณผ ์‹คํ–‰์˜ ๋‹จ์ ˆ ๋ฌธ์ œ, ์œ„์ž„ ๊ตฌ์กฐ์˜ ์ถ”์  ๋ถˆ๊ฐ€๋Šฅ์„ฑ, ๋ฌธ๋งฅ ๋ฌด๊ฒฐ์„ฑ ์œ„ํ˜‘, ๊ฐ์‚ฌ ๋กœ๊ทธ์˜ ๋น„์ผ๊ด€์„ฑ์ด๋ผ๋Š” ๋ฌธ์ œ๋“ค์„ ํ•˜๋‚˜์˜ ํ†ตํ•ฉ๋œ ๊ตฌ์กฐ์—์„œ ํ•ด๊ฒฐํ•˜๋ฉฐ, AI ํ™˜๊ฒฝ์— ์ตœ์ ํ™”๋œ ๋ณด์•ˆ ํ†ต์ œ ์ˆ˜๋‹จ์œผ๋กœ ์ž๋ฆฌ์žก์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๊ฒฐ๋ก  ๋ฐ ๋ฐฑ์„œ ์š”์•ฝ

AI ์‹œ์Šคํ…œ์€ ์ ์  ๋” ์ž์œจํ™”๋˜๊ณ  ์žˆ์œผ๋ฉฐ, ๊ทธ ์‹คํ–‰ ๊ตฌ์กฐ๋Š” ๋‹จ์ˆœํ•œ ๊ณ„์ •/๊ถŒํ•œ ์ค‘์‹ฌ ๋ณด์•ˆ์œผ๋กœ๋Š” ์ œ์–ดํ•  ์ˆ˜ ์—†๋Š” ๋ณต์žก์„ฑ์„ ๊ฐ–์Šต๋‹ˆ๋‹ค. ํŠนํžˆ MCP(Model Context Protocol) ๊ธฐ๋ฐ˜์˜ ์‹œ์Šคํ…œ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ํŠน์„ฑ์„ ๋™์‹œ์— ๋‚ดํฌํ•ฉ๋‹ˆ๋‹ค:

  • ์‚ฌ์šฉ์ž ๋Œ€์‹  ์—์ด์ „ํŠธ์™€ LLM์ด ์‹คํ–‰ ์ฃผ์ฒด๊ฐ€ ๋˜๋Š” ๊ตฌ์กฐ
  • ์‹คํ–‰ ์ „ํ›„ ๋ฌธ๋งฅ(Context)์— ๋”ฐ๋ผ ์ •์ฑ… ํŒ๋‹จ๊ณผ ์‹คํ–‰ ๊ฒฐ๊ณผ๊ฐ€ ๋‹ฌ๋ผ์ง€๋Š” ์ƒํ™ฉ
  • ์œ„์ž„, ํ”„๋ก์‹œ, API ํ†ตํ•ฉ ํ™˜๊ฒฝ์—์„œ ๋ฐœ์ƒํ•˜๋Š” ์ˆ˜ํ‰์  ๊ถŒํ•œ ํ๋ฆ„

์ด๋Ÿฌํ•œ ํ™˜๊ฒฝ์€ ๊ธฐ์กด PAM ์ฒด๊ณ„๊ฐ€ ๋Œ€์‘ํ•  ์ˆ˜ ์—†์—ˆ๋˜ ๋ฌธ๋งฅ ์˜ค์—ผ(Context Tampering), ์ •์ฑ… ๋น„์ ์šฉ(Policy Ignorance), ์‹คํ–‰ ๋ถˆ์ผ์น˜(Runtime Inconsistency), ๋กœ๊น… ๋ˆ„๋ฝ(Audit Omission) ๊ฐ™์€ ๋ฌธ์ œ๋ฅผ ๋™๋ฐ˜ํ•ฉ๋‹ˆ๋‹ค.

๋ณธ ๋ฐฑ์„œ์˜ ๊ฒฐ๋ก ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค:

โ€œAI ์ค‘์‹ฌ์˜ MCP ๊ธฐ๋ฐ˜ ํ™˜๊ฒฝ์—์„œ๋Š” ๊ธฐ์กด ๋ณด์•ˆ์†”๋ฃจ์…˜์„ ๋„˜์–ด์„œ, ๋ฌธ๋งฅ ๊ธฐ๋ฐ˜ ์‹คํ–‰ ์ •์ฑ…์„ ์ž์œจ์ ์œผ๋กœ ํŒ๋‹จยท๊ฐ•์ œยท๊ธฐ๋กํ•  ์ˆ˜ ์žˆ๋Š” ์ƒˆ๋กœ์šด MCP Security ์ฒด๊ณ„๊ฐ€ ํ•„์š”ํ•˜๋ฉฐ, ๊ทธ ํ•ด๋‹ต์€ MCP PAM์ด๋‹ค.โ€



๐Ÿš€ AI Hub๋กœ ์•ˆ์ „ํ•œ MCP์™€ AI Agent ์šด์˜, ์ง€๊ธˆ ์ง์ ‘ ์ฒดํ—˜ํ•ด๋ณด์„ธ์š”.

์ฐธ๊ณ  ๋ฌธํ—Œ

[1] X. Hou, L. Zhang, R. Sun, and Y. Wang, โ€œModel Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions,โ€ arXiv preprint, Mar. 2025.

[2] B. Radosevich and J. Halloran, โ€œMCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits,โ€ arXiv preprint, Apr. 2025.

[3] S. Szeider, โ€œMCP-Solver: Integrating Language Models with Constraint Programming Systems,โ€ arXiv preprint, Apr. 2025.

[4] A. Singh, Y. Gupta, and N. Trivedi, โ€œA Survey of the Model Context Protocol (MCP): Standardizing Context to Enhance Large Language Models (LLMs),โ€ Preprints.org, Apr. 2025.

[5] P. Pajo, โ€œSmithery.ai: A Model Context Protocol for Enhanced LLM Integration and Cross-Industry Applications,โ€ ResearchGate, Mar. 2025.

[6] Z. Chen, J. Lin, and R. Wang, โ€œShieldAgent: Shielding Agents via Verifiable Safety Policy Reasoning,โ€ arXiv preprint, Mar. 2025.

[7] J. Luo, K. Hu, and M. Zhao, โ€œLarge Language Model Agent: A Survey on Methodology, Applications and Challenges,โ€ arXiv preprint, Mar. 2025.

[8] X. Hou, R. Sun, and J. Yao, โ€œThe Next Frontier of LLM Applications: Open Ecosystems and Hardware Synergy,โ€ arXiv preprint, Mar. 2025.

[9] Anthropic, โ€œIntroducing the Model Context Protocol,โ€ Anthropic Technical Blog, Nov. 2024.

[10] T. South, J. Velasquez, and M. D. Kemp, โ€œAuthenticated Delegation and Authorized AI Agents,โ€ arXiv preprint, Jan. 2025.

[11] G. A. Gabison and R. P. Xian, โ€œInherent and Emergent Liability Issues in LLM-Based Agentic Systems,โ€ arXiv preprint, Apr. 2025.

[12] P. Pajo, โ€œModel Context Protocol Servers: A Novel Paradigm for AI-Driven Workflow Automation,โ€ ResearchGate, Mar. 2025.

[13] P. Pajo, โ€œAccelerating AI Integration: Multi-Order Effects and Sociotechnical Implications of Standardized AI-Tool Interoperability,โ€ ResearchGate, Mar. 2025.

[14] A. Ramachandran, โ€œTransforming Enterprise AI Integration: Architecture, Implementation and Applications of MCP,โ€ ResearchGate, Mar. 2025.

[15] A. Kattamuri, โ€œUnlocking Context for Intelligent Agents: The Model Context Protocol as a Standardized Integration Framework,โ€ IJIRSET, Mar. 2025.

[16] QueryPie, โ€œSecurity Governance and Integrated PAM Strategy for AI Agents in the Age of the Model Context Protocol (MCP),โ€ White Paper, 2025.

[17] QueryPie, โ€œMCP PAM as the Next Step Beyond Guardrails,โ€ White Paper, 2025.

MCP ๋ณด์•ˆ์„ฑ ํ‰๊ฐ€: ๋ฌธํ—Œ ์กฐ์‚ฌ๋ฅผ ํ†ตํ•œ MCP ๋ณด์•ˆ ์œ„ํ˜‘ ์‹๋ณ„ ๋ฐ ์ทจ์•ฝ์  ๋ถ„์„ | QueryPie